WO2017024957A1 - Method and device for data processing - Google Patents

Method and device for data processing Download PDF

Info

Publication number
WO2017024957A1
WO2017024957A1 PCT/CN2016/092673 CN2016092673W WO2017024957A1 WO 2017024957 A1 WO2017024957 A1 WO 2017024957A1 CN 2016092673 W CN2016092673 W CN 2016092673W WO 2017024957 A1 WO2017024957 A1 WO 2017024957A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
desensitization
production
application
project
Prior art date
Application number
PCT/CN2016/092673
Other languages
French (fr)
Chinese (zh)
Inventor
张金银
肖禹
江敏
曾文秋
廖育才
Original Assignee
阿里巴巴集团控股有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 阿里巴巴集团控股有限公司 filed Critical 阿里巴巴集团控股有限公司
Publication of WO2017024957A1 publication Critical patent/WO2017024957A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6236Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database between heterogeneous systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2107File encryption

Definitions

  • the present application relates to the field of computers, and in particular to a technique for data processing.
  • the prior art cannot accurately control the processing process and environment of the data by the user, such as copying the visible data in the authorization phase, or the data sampling desensitization process is not flexible enough, and the data provider does not trust the usage data usage environment. Therefore, the contradiction between using the data and not allowing the data consumer to see or export the data is gradually highlighted.
  • the purpose of the present application is to provide a method and device for data processing, which is to solve the problem that data needs to be invisible during data usage and data security is ensured when confidential or non-confidential data exchange is performed.
  • a method for data processing which solves the problem that a service party needs data to be invisible during data usage, and the method includes:
  • the desensitization data is processed by the development project.
  • a method for data processing by using a data providing device end and a data application device end which solves the problem that data needs to be invisible when different business parties use non-confidential data exchange. Problem, the method includes:
  • the production data in the production project is desensitized to obtain corresponding desensitization data
  • the desensitization data is sent to the application development project via the development project according to result information of the development authorization process.
  • desensitization data from a development item in the data providing device is obtained by an application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
  • the desensitization data is processed by the application development project.
  • a method for data processing by a data providing device end and a data application device end for use in a platform device end which solves the problem that different business parties perform confidential data exchange and use. Data is invisible and data security is guaranteed.
  • This method includes:
  • the platform device is configured to process desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
  • the desensitization data is processed by the configured platform device.
  • an apparatus for performing data processing which solves the problem that a service party needs data invisibility to be invisible during data use, and the apparatus includes:
  • a data desensitizing device for desensitizing the production data in the production project to obtain corresponding desensitization data
  • a desensitization data transmitting device configured to send the desensitization data to a corresponding development project
  • a desensitization data processing device for processing the desensitization data by the development project.
  • an apparatus for data processing is used by a data providing device end and a data application device end, and the device solves the problem that different data is invisible when non-confidential data exchange is used by different service parties.
  • the device includes:
  • the data providing device data desensitizing device is configured to desensitize the production data in the production project to obtain corresponding desensitization data
  • the data providing device development development authorization device is used for the application in the corresponding data application device through the development project Development project for development authorization processing;
  • a desensitizing data transmitting device of the data providing device configured to send the desensitizing data to the application development project via the development project according to result information of the development authorization process
  • a desensitization data acquisition device on the data application device side for acquiring desensitization data from a development item in the data providing device through an application development project, wherein the desensitization data is obtained by taking production data of a production item in the data providing device Sensitive treatment obtained;
  • an apparatus for data processing by using a data providing device end and a data application device end on a platform device end is provided, and the device solves the problem that different business parties perform confidential data exchange and use. Data is invisible and data security is guaranteed.
  • the device includes:
  • the data providing device data desensitizing device is configured to desensitize the production data in the data providing device to obtain corresponding desensitization data
  • the data providing device desensitizing data sending device is configured to send the desensitizing data to a corresponding platform device for processing by a corresponding data application device;
  • a platform configuration device of the data application device configured to configure the platform device to process desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
  • a device device configured on the platform device, configured to configure the platform device according to the corresponding data application device;
  • the desensitization data processing device on the platform device side is configured to process the desensitization data by using the configured platform device.
  • an embodiment of the present application desensitizes the production data in the data providing device at the data providing device end to obtain corresponding desensitization data; and acquires desensitization from the data providing device at the platform device end.
  • Data wherein the desensitization data is obtained by desensitizing the production data in the data providing device; configuring the platform device according to the corresponding data application device; processing the desensitization data through the configured platform device to solve The problem of confidential data exchange and the invisibility of data availability and data security when using different business parties, so that data is placed in a third-party security environment for circulation and use when the data provider and the user do not fully trust. It ensures the security of data flow and use.
  • FIG. 1 shows a flow chart of a method for performing data processing in accordance with an aspect of the present application
  • FIG. 2 shows a flow chart of a method for performing data processing in accordance with a preferred embodiment of the present application
  • FIG. 3 is a flowchart of a method for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application;
  • FIG. 4 is a flow chart showing a method for performing data processing according to another embodiment of the data providing device and the data application device according to another preferred example of the present application;
  • FIG. 5 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application;
  • FIG. 6 is a flowchart of a platform device-side method in a method for implementing data processing, which is implemented by a data providing device end, a data application device end, and a platform device end according to another preferred example of the present application;
  • FIG. 7 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred example of the present application;
  • FIG. 8 shows a schematic diagram of an apparatus for performing data processing in accordance with another aspect of the present application.
  • FIG. 9 is a schematic diagram of an apparatus for performing data processing according to another preferred embodiment of the present application.
  • FIG. 10 is a schematic diagram of an apparatus for performing data processing according to a data providing device end and a data application device end according to another aspect of the present application;
  • FIG. 11 is a schematic diagram showing an apparatus for performing data processing, which is implemented by a data providing device end and a data application device end according to another preferred example of the present application;
  • FIG. 12 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application;
  • FIG. 13 is a schematic diagram of a platform device end in a device for implementing data processing, which is implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application;
  • FIG. 14 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
  • the terminal, the device of the service network, and the trusted party each include one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
  • processors CPUs
  • input/output interfaces network interfaces
  • memory volatile and non-volatile memory
  • the memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory.
  • RAM random access memory
  • ROM read only memory
  • Memory is an example of a computer readable medium.
  • Computer readable media includes both permanent and non-persistent, removable and non-removable media.
  • Information storage can be implemented by any method or technology.
  • the information can be computer readable instructions, data structures, modules of programs, or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage,
  • computer readable media does not include non-transitory computer readable media, such as modulated data signals and carrier waves.
  • the present application includes three cases of data processing, one of which is based on the control of the rights in the data use, so that the data provided by the business party is invisible in the process; and the second is based on the authorization mode, so that different business parties are in the process of non-confidential data exchange.
  • the medium-sized security circulation is also invisible; the third is based on the way of entrusting a third-party platform to ensure the security of different business parties in the process of confidential data exchange and processing.
  • the control based on the permission of the data in use makes the data provided by the business party invisible in the process of processing, that is, in the case that a business party needs to perform data processing, the business party secretly desensitizes the key features of the real data and
  • the process of providing the data developer with processing and finally processing the processing result is as follows.
  • the data processing device includes step S11, step S12, and step S13.
  • step S11 the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding development project; The data processing device processes the desensitization data through the development project in step S13.
  • step S11 the data processing device desensitizes the production data in the production project to obtain corresponding desensitization data, which means that the service hides the key sensitive features of the real data in the controlled security environment, thereby obtaining the reserved The necessary data characteristics used by the data user hide or eliminate the data characteristics that would cause security issues to be sensitive
  • the production data is the real data that the business party needs to process.
  • the production project is the security environment controlled by the business party. It can be created by the business party and has relevant control rights such as accessing data object permissions, user management and authorization rights, and resource creation. For example, business company A needs research institute B to develop software for data of an application, and can create a production project in a data development platform that can be used by both parties.
  • the created account is accessible to the owner of the production project. Produce all the resources in the project and authorize the user or account and set the security settings of the production project.
  • the owner can assign a production account to have all the permissions except the security settings, so that the production account can develop an application for company A.
  • the real data is desensitized. Desensitize real data in a secure environment controlled by the business side, so that key security information of the data can be concealed to improve data security.
  • the data processing device sends the desensitization data to the corresponding development project, which means that the desensitization data is sent to the security of the data processing and control by the data development platform, for example, through a common trust data development platform.
  • the development project is a security environment that is trusted by the data provider for data processing by the data processing party.
  • the company A needs to perform software development processing on the data of an application in the data development platform. Create a production project and create a corresponding development project and assign development-related permissions such as creating tables, functions, resources, etc. in the development project to the development account of the B Institute, so that the desensitization data can be directly from the production project via the data development platform. Send to the development project.
  • the manner of sending the desensitization data includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices, but is not limited thereto.
  • the data processing device processes the desensitization data through the development project, that is, the data processor performs processing such as software development, data mapping, etc. on the desensitization data in a secure development project environment, but is not limited thereto.
  • the account or role of the development project to deal with the desensitization data is assigned or created by the business party providing the data.
  • the company A creates the production project and the owner of the development project assigns the B research institute or the company personnel to the development project.
  • Administrator the administrator has access to all objects in the development project, and can manage and authorize the user or role, such as assigning the data developer of the B research institute to develop the account, and the development account has the permission to create the table or function. Therefore, the desensitization data provided by Company A can be developed, thereby facilitating the secure management of the development account, and making the development account available to the real data but not visible.
  • FIG. 2 shows a flow chart of a method for performing data processing in accordance with a preferred embodiment of the present application. It includes step S11, step S12, step S13, step S14, and step S15.
  • step S11 the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding development project; The data processing device processes the desensitization data by the development item in step S13; the data processing device returns the processing result of the desensitization data in the development item to the production item in step S14; in step S15 The medium data processing device issues the processing result through the production item.
  • step S11 and step S13 are the same as or similar to steps S11 and S13 in FIG. 1 and will not be described again.
  • the data processing device returns the processing result of the desensitization data in the development project to the production item in the data processing device in step S14, which refers to the processing result after the desensitization data is processed in the development project.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception.
  • the developer of the B research institute sends the code to the production project through the data development platform after developing the software code of the application through the development account in the development project based on the desensitization data, so that the company A processes the data processing result. Review or evaluate to further ensure the security of data and data processing results.
  • step S15 the data processing device issues the processing result through the production item, which means that the data provided by the data provider receives the returned desensitization data processing result in the production item, and then performs the code on the data processing result through the real data or Program performance verification or external output is not limited to this.
  • the release processing result is to verify the data processing result or to produce it through real production data.
  • Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data to test the software program of the released data.
  • the data processing results are released in the production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
  • the data processing device further comprises a step S16 (not shown) for setting the rights information of the development item regarding the desensitization data. That is, after the production project desensitizes the real data, the same desensitization data may More than one type of data processing, for example, software development, data analysis, etc. At this time, different uses have different data usage. Therefore, different usage rights information can be used to obtain different usage and processing of desensitization data during development. Permissions. In the above example, the data of the company A's desensitization data set during software development is read, created, etc., and the data analysis is only read-only.
  • sending the desensitization data to the development item according to the authority information in step S12 means that the desensitization data is selective according to different rights regarding desensitization data open to the development project.
  • Sent to the development project, for example, Company A will desensitize data for a month's data analysis to send only desensitization data for the current month, while the desensitization data required for development software is one year or quarter, thus making desensitization The transmission of data is more targeted and better manages the data.
  • FIG. 3 is a flowchart of a method for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application.
  • the data providing device end includes step S11, step S12, and step S13; and the data application device end includes step S21 and step S22.
  • step S11 the data processing device desensitizes the production data in the production project to obtain corresponding desensitization data; in step S12, the data processing device performs the application development project in the corresponding data application device through the development project.
  • step S12 the data processing device performs the application development project in the corresponding data application device through the development project.
  • Developing a authorization process the data processing device transmits the desensitization data to the application development project via the development project according to the result information of the development authorization process in step S13; the data processing device passes the application development project in step S21 Obtaining desensitization data from a development item in the data providing device, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device; the data processing device is developed by the application in step S22 The project processes the desensitization data.
  • step S11 the data processing device desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the data providing device side, that is, the data providing device end is sensitive to the real data in the controlled security environment.
  • the concealment of features results in data that retains the necessary data features available to the data consumer and conceals or eliminates data characteristics that would result in security-sensitive data.
  • the production project is a security environment controlled by the data provider business.
  • Company A cooperates with Company C to jointly develop an application software.
  • Company A provides key data for software development and is responsible for part of software development.
  • the company is responsible for software development, so in data development In the platform, Company A creates a project space for the application, which is the data supply device.
  • the production project is the security environment for Company A to process real key data.
  • the creation owner of Project A of the company assigns the production account of the company. It has all the rights except the security settings in the production project, that is, before the data is provided by Company A, the data is desensitized in the production project, so that the key security information of the data can be concealed to improve the security of the data.
  • step S12 the data processing device performs development authorization processing on the application development project in the corresponding data application device through the development project, which means that both the data providing device end and the data application device end have both the production project and the corresponding development project, because The production data is real data and should not be sent directly to different business parties from the security point of view. Therefore, after the data is desensitized, the desensitization data is sent to the development project of the project, and the data application application development project of the device side uses the desensitization data. It is necessary to obtain the authorization of the business party represented by the data providing device side.
  • the authorization method includes authorizing the development project to the data application device, so that it can be sent through the data development platform or through SFTP or other secure file transfer methods, but is not limited thereto, or the development account in the data application device development project is performed.
  • Authorization so that the development account can directly read the desensitization data in the data-providing device-side development project.
  • C company initiates the development and control of company A in the data development platform when it needs A company data for software development.
  • Company A authorizes the development account in the development project of Company C through the ACL authorization between the tables in the data development platform, so that the desensitization data can be safely transferred in the development environment.
  • step S13 the data processing device sends the desensitization data to the application development project via the development project according to the result information of the development authorization process, which means that the data is provided after the development project of the data application device is authorized.
  • the device side sends the desensitization data in the controlled development project to the development project of the data application device.
  • the method of sending includes, but is not limited to, sending through a data development platform or developing a project in a data application device.
  • the development account is directly read according to the authorization, or is performed by SFTP or other secure file transmission method, but is not limited thereto.
  • the development account of Company C is read by the company A through the development project of the data providing device, and then the desensitization data is read according to the authority, so that the desensitization data is visible, the production data is invisible, and the real data is guaranteed in the data exchange process. Security.
  • the desensitization data obtaining means 321 acquires desensitization data from the development item in the data providing device by the application development project, wherein the desensitization data is desensitized by the production data of the production item in the data providing device
  • the processing is obtained, that is, as described above, after obtaining the authorization of the data application device, the desensitization data provided by the data providing device development project is obtained according to the authorization, and the above example is the development project in the project space created by the management company C.
  • the development account reads the desensitization data according to the authority after obtaining the authorization.
  • the data processing device processes the desensitization data through the application development project in step S22, that is, the development project managed by the data application device performs the desensitization data after acquiring the desensitization data of the data providing device end.
  • the application development project is a data development environment controlled by the data application device end, and the business party where the data application device end is located controls the development authority, thereby effectively supervising the safe circulation of data, and the above example, that is, the data
  • the project space where C Company is located in the development platform utilizes the development account of the authorized C company in the development space to develop the desensitized data of the read company A, so as to achieve desensitization data when the business side performs non-confidential data exchange processing. Visible and invisible to real data.
  • the data application device further includes a step S25 (not shown) for desensitizing the application production data in the application production project to obtain corresponding application desensitization data. That is, in the production project controlled by the data application device, the production data of the data application device can be desensitized to obtain the desensitization data of the data application device end.
  • the company A and the C company jointly carry out software development, C company While obtaining the desensitization data of Company A for development, combined with the real production data of Company C for software development, the data is desensitized in the production project of Company C controlled by the data development platform, thereby obtaining the company C. Desensitization data.
  • step S22 the data processing device processes the desensitization data and the application desensitization data through the application development project, that is, the development project of the data application device pair obtains the corresponding data application device end production project.
  • the desensitization data provided and processed, and the above example, that is, the development project of the company C in the data development platform develops and processes the desensitization data of the real data of the C company provided by the C company production project, thereby achieving In the joint development process of A and C companies, C company can combine the desensitization data of both parties to process and ensure the security of real data in the process of circulation.
  • FIG. 4 shows a flow chart showing a method for data processing implemented by the data providing device end and the data application device side according to another preferred example of the present application.
  • the data providing device end includes step S11, step S12, and step S13;
  • the data application device end includes step S21 and step S22; step S23; step S24.
  • the data processing device desensitizes the production data in the production item in step S11 to obtain Corresponding desensitization data; in step S12, the data processing device performs development authorization processing on the application development project in the corresponding data application device through the development project; in step S13, the data processing device according to the result information of the development authorization process
  • the desensitization data is sent to the application development project via the development project; in step S21, the data processing device acquires desensitization data from the development project in the data providing device through the application development project, wherein the desensitization data passes through the The production data desensitization process of the production item in the data providing device is obtained; in step S22, the data processing device processes the desensitization data through the application development project; in step S23, the data processing device stores the desensitization data in the The processing result in the application development project is provided to the application production project; in step S24, the data processing device issues the processing result through the application production project.
  • step S11, the step S12, the step S13, the step S21 and the step S22 are the same as or similar to the steps S11, S12, S13, S21 and S22 in FIG. 3 and will not be described again.
  • the processed result of the desensitization data provided by the device end is returned to the production project controlled by the data application device.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception.
  • the developer of Company C develops the software code of the application through the development account in the development project based on the desensitization data, and then sends the code to the production project of the C company through the data development platform, so that the company C is united.
  • the data processing results developed are uniformly reviewed or evaluated to further ensure the security of data and data processing results.
  • the data processing device issues the processing result through the application production item, that is, the data application device end receives the desensitized data processing result in the production project, and then performs the code on the data processing result through the real data or Program performance verification or external output is not limited to this.
  • the release processing result is to verify the data processing result or to obtain the data providing device end device in the production project after the authorization of the data on the data application device, and then to produce the data based on the real production data.
  • C company publishes the returned program code based on the desensitization data of company A on the data development platform in the production project, and the production account uses the real data authorized by company A to execute the software program on the released data. Test work.
  • the data processing result is released in the production space, so that the processing result is post-processed or verified in the security environment of the data provider, so that the company A and the C company cooperate in the process of data processing, and the development project authorizes the development project so that C
  • the company's development account can read the company's desensitization data, so that the development process has targeted protection and development of data permissions, development projects to improve the security of data processing results.
  • the data providing device end further includes a step S14 (not shown) for performing a production authorization process on the application production item in the data application device by the production item; step S15 (not shown), And transmitting the production data to the application production item via the production item according to result information of the production authorization process.
  • the data application device side further includes a step S26 (not shown) for acquiring production data of the production item in the data providing device by applying the production item.
  • the data processing device performs production authorization processing on the application production item in the data application device by using the production item, that is, the controlled production item of the data providing device end reads data through an authorized account, etc.
  • the production project on the data application device is authorized.
  • the authorization method includes, but is not limited to, the production project management account in the data providing device side, so that the management account of the data application device side production space can read the production data in the data providing device end by means of the access control between the tables, and the like.
  • the production account of the production project in the project space controlled by Company A authorizes the production account of the production project in the project space controlled by Company C, so that it can obtain the authority to read the real production data, thereby completing the authorization.
  • the sending, by the data processing device, the production data to the application production item via the production item according to the result information of the production authorization processing in step S15 refers to sending the production data to the data according to the authorization information of the data providing device end.
  • the above example is given, that is, after the authorization of the production project managed by the company C by the company A in the data development platform, the authorized production data of the company A is sent to the production project of the company C, Or the production account in the production project of Company C obtains the reading authority of the production data of Company A to read the production data of Company A.
  • step S26 the data processing device acquires the production data of the production item in the data providing device by applying the production item, wherein the step S23 performs the processing result in the application production item according to the production data.
  • the data application device obtains the production data of the data providing device according to the authorization
  • the processing result is verified by the production data of the data providing device.
  • the execution manner includes, but is not limited to, performing code or program performance verification or external output through real data.
  • the company C is released through the production account pair in the controlled production project.
  • the software code based on the desensitization data of Company A is tested or the software is tested by the production data provided by Company A to Company C, so that the production data is only distributed in the production project environment of A and C companies, and the desensitization data is only Circulated in the development environment of A and C companies, and guaranteed to be common
  • the line data development process only the visible side of the business development side of real data but the data is visible only to desensitization, so as to enhance the security of data in the non-confidential exchange.
  • FIG. 5 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application.
  • the data providing device includes steps S11 and S12; the data application device includes step S21; and the platform device includes steps S31, S32, and S33.
  • step S11 the data processing device desensitizes the production data in the data providing device to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding platform device to Processing by the corresponding data application device; the data processing device acquires desensitization data from the data providing device in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; The data processing device in S21 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; in step S32, the data processing device configures the platform device according to the corresponding data application device The data processing device processes the desensitization data through the configured platform device in step S33.
  • step S11 the data processing device desensitizes the production data in the data providing device to obtain the corresponding desensitization data, which means that the business party providing the data hides the key sensitive features of the real data at the data providing device end to obtain Retains the necessary data characteristics available to data consumers and conceals or eliminates data that can cause security-sensitive data characteristics.
  • production data refers to real data containing key sensitive features.
  • Data desensitization methods include, but are not limited to, desensitization directly on the data development platform or through manual screening. For example, Company A and Company D have certain types of data.
  • step S12 the data processing device sends the desensitization data to the corresponding platform device for processing by the corresponding data application device, which means that the desensitization data is sent to the data processing device end and the data providing device at the data providing device end.
  • the third-party data processing platform device side trusted by the service represented by the terminal enables the data application device to perform data processing in the third-party platform.
  • the corresponding platform device refers to a third-party data processing platform that is trusted by both parties that need to perform data flow, such as a jointly created controllable correlation number.
  • Company A and Company D jointly entrust a third party as the control and arbitration party in the exchange process, and the third party supervises one.
  • the project space is safely set up, and Company A sends the desensitization data to the project space controlled by the third party for Company D to process it in a third party.
  • the method of sending the desensitization data may be directly transmitted in the background through the data development platform or transmitted through a related protocol for secure transmission of the encrypted file, but is not limited thereto.
  • the data processing device acquires desensitization data from the data providing device in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  • the platform device side is used as a data providing device and a security environment controlled by a third party trusted by the data application device end, and accepts or acquires the desensitization data of the data providing device end under a certain authority, thereby facilitating the data application device end.
  • the project space created by the third party in the data platform is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A.
  • the company's desensitization data is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A.
  • the data processing device configures the platform device to process the desensitization data in step S21, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. That is, the data application device side performs the direct authorization of the development account or the project space package authorization on the platform device side, so that the data application device can process the desensitization data in the security environment controlled by the platform set end, For example, Company D authorizes the project space controlled by third parties in the data development platform, so that developers of Company D can process the data in the third-party project space.
  • the method for configuring the platform device may be to directly authorize the project space controlled by the platform or authorize the development-related account in the platform, so that the data application device can perform data processing through the account, but is not limited thereto.
  • the data processing device configures the platform device according to the corresponding data application device, and the platform device device performs the setting according to the data application device end, so that the data application device device can process the desensitization data in a security environment controlled by the platform device.
  • the manner in which the platform device is configured according to the corresponding data application device includes, but is not limited to, the development account of the authorized data application device end can perform data processing in the project space controlled by the platform device or the data application device directly performs authorization processing on the platform device end.
  • the platform device is configured to enable the data application device to process the desensitized data in the security management environment during the confidential data exchange, thereby improving the security of the confidential data.
  • step S33 the data processing device processes the desensitization data through the configured platform device, and the data application device is desensitized according to the permission of the device device in the third-party security environment controlled by the platform device.
  • Data processing in the above example, A, D company authorized the third-party project space in the data development platform, the developer of the D company is added to the third-party project space for data processing, so that the data application device can The use of data to provide confidential data on the device side, while the confidential data can not be copied in a secure third-party environment, thereby improving the security of the use and processing of confidential data.
  • FIG. 6 is a schematic diagram of a platform device-side method in a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
  • the platform device end includes step S34, step S31, step S32, and step S33.
  • the data processing device creates an item in the platform device in step S34; the data processing device acquires desensitization data from the data providing device through the item in step S31, wherein the desensitization data passes through the opposite
  • the production data desensitization process is obtained in the data providing device; the data processing device configures the item according to the corresponding data application device in step S32; and the data processing device processes the desensitization data through the configured item in step S33 .
  • step S34 the data processing device creates a project in the platform device, which means that a secure data flow and a processing space are created in the platform device trusted by the data providing device and the data application device, so that the confidential data can be secure.
  • the protection is received.
  • Company A and Company D jointly commissioned the data development platform or a third party trusted by both parties to create a secure project space in the data development platform, so that A, Company D can process and share data in the project space.
  • the data processing device acquires desensitization data from the data providing device through the item in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  • the project space created by the platform device side obtains desensitization data in the data providing device side by directly authorizing the project space of the data providing device side.
  • Company A is in the data development platform to the third party. The project space is authorized so that the desensitization data can only be accessed in the third-party project space, thereby limiting the circulation and processing range of the confidential data, thereby improving the security of the data.
  • step S32 the data processing device configures the item according to the corresponding data application device, that is, the platform device side sets the project space according to the authorization of the data application device end, and the third-party project space is obtained as an example.
  • the authorization of D company's project space is added to the developer of D company in the third project space, so that developers of Company D can process the desensitization data of Company A in the third-party project space.
  • step S33 the data processing device processes the desensitized data through the configured item, that is, the developer or the account of the data application device is configured, and then the platform device end is in the controlled project space.
  • the data provides desensitization data provided by the device side for processing.
  • the desensitization data of the confidential data provided by the company A is processed in the third-party project space, thereby Limiting the flow of confidential data to the project space further enhances the security of confidential data.
  • FIG. 7 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
  • the data providing device end includes step S11, step S13, and step S12; the data application device end includes step S21; and the platform device end includes step S34, step S35, step S31, step S32, step S33, and step S36 and step S37.
  • step S34 the data processing device creates an item in the platform device; in step S11, the data processing device desensitizes the production data in the data providing device to obtain corresponding desensitization data; in step S13 The data processing device performs authorization processing on the items in the platform device; in step S35, the data processing device acquires authorization information of the data providing device and the data application device for the item; in step S12, the data processing device The desensitization data is sent to the corresponding platform device for processing by the corresponding data application device; in step S31, the data processing device acquires desensitization data from the data providing device through the item according to the authorization information, where The desensitization data is obtained by desensitizing the production data in the data providing device; the data processing device configures the platform device to process desensitization data in step S21, wherein the desensitization data is passed through the data providing device The production data desensitization process is obtained; in step S32, the data processing device is configured according to
  • step S11, step S12, and step S21 are the same as or similar to step S11, step S12, and step S21 in FIG. 5 and will not be described again.
  • Step S34 is the same as or similar to step S34 in FIG. 6, and will not be described again.
  • Authorizing the item in the platform device by the platform authorization device 713 in the data providing device refers to authorizing the project space controlled by the trusted platform device at the data providing device end.
  • the authorized party The platform device item can be packaged and authorized directly through the project in the data providing device, so that the confidential data provided by the data providing device can be obtained by the platform device project, and the above example is in the data development platform.
  • the company's project space packages and authorizes the third-party project space, so that the account of the third-party project space can read the desensitization data or the third-party project space has the right to accept desensitization data.
  • step S35 the data processing device acquires the authorization information of the data providing device and the data application device for the item, and refers to receiving the authorization of the data providing device end and the data application device end of the platform device end.
  • the flow and processing of confidential data are transferred in a secure environment of mutual trust.
  • the project space of Company A and Company D package and authorize the third-party project space, thereby making the company A take off.
  • Sensitive data can be streamed in third-party project spaces and developers of Company D can develop Desensitization data for Company A in a third-party space.
  • Data is transferred and processed in a secure and controllable environment through project authorization on the platform device side to improve data security.
  • step S31 the data processing device acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data is taken off by the production data in the data providing device Sensitive treatment is obtained. That is, the project on the platform device side obtains the desensitization data according to the authorization of the data providing device end, wherein the obtaining manner includes, but is not limited to, reading the desensitized data within the authority according to the authorization of the project, In the data development platform, Company A grants the third-party project the right to read and copy the desensitized data of the confidential data, so that the third-party project acquires the desensitization data of Company A.
  • the items in the data providing device, the data application device, and the platform device include a production project and a development project.
  • the production project refers to a project space in the project that processes real data, and is controlled by each business party;
  • the development project is Refers to the project space where the developer handles the desensitization data in the project, and is used by the development account assigned by the business party.
  • the data processing device is further configured to acquire authorization information of the data providing device and the data application device for the production item. That is, the production project on the data development device side and the data application device side package and authorize the production items in the platform device side of the common trust, so that the real data to be processed within the allowable range of the two can be shared in a safe production project environment.
  • Company A and Company D authorize the production projects in the third-party projects in the data development platform, and obtain the real data required by the two parties to jointly develop the software after obtaining the authorization.
  • the data processing device is further configured to acquire desensitization data from the data providing device through the development item according to the authorization information, wherein the desensitization data is passed through the data providing device Production data desensitization is obtained.
  • the desensitization data in the platform device is desensitized by the data providing device
  • third-party development projects obtain desensitization data from company A, thereby adding developers to Developers in third-party development projects can use the development project to process and use the desensitization data of Company A, thus ensuring that desensitization data can be used by developers of Company D in a third-party security environment, but because it is in a third party.
  • the desensitized data cannot be copied or used for other purposes in a controlled environment, thus ensuring the security of confidential data.
  • the data processing device is further configured to configure the development item according to the corresponding data application device. That is, the data application device can process the desensitization data provided by the data providing device in the platform device by adding the development account in the data application device to the development project or the like through the platform device end.
  • the development project space shared by A and D companies in the data development platform adds the developer account of Company D to the project space of the third party according to the application of Company D, and then processes the desensitization data of Company A.
  • the data processing device is further configured to process the desensitization data through the configured development item in step S33.
  • the desensitization data provided by the data providing device is processed in the development project of the platform device side, and the developer of the D company in the data development platform is connected as an example.
  • the account number is added to the development of the desensitization data of Company A in the third-party development project space, so that the desensitization data cannot be copied or reserved for use in a third-party controlled environment, and the confidential data is guaranteed. Security.
  • step S36 the data processing device provides the processing result of the desensitization data in the application development project to the application production project.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception.
  • the developer of Company D develops the software code of the application through the development account in the third-party development project based on the desensitization data, and then sends the code back to the production project through the data development platform, so that Company A is in the third party.
  • Data processing results are reviewed or evaluated in the production project space to further ensure the security of data and data processing results.
  • step S37 the data processing device issues the processing result of the desensitization data in the development project through the production item.
  • the release processing result is to verify the data processing result or to produce it through real production data.
  • Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data in the third-party project space to execute the software program on the released data. Test work.
  • the data processing results are published in the third-party production space, so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the logarithm According to the safety of the processing results.
  • the data application device further includes a step S22 (not shown) for performing authorization processing on the items in the platform device. That is, the data application device uses the data to provide the data of the device end, and in the case that the data needs to be processed together with the data, the platform can be authorized to obtain the data to apply the confidential data of the device or the desensitization data thereof.
  • the data development platform D company needs to combine the confidential data of Company D with the desensitization data of Company A to develop or research the software in the third-party development environment. Therefore, the project space controlled by Company D is the first.
  • the three-party platform project is authorized to provide desensitization data of D company's confidential data, so that the dual-issue data of the company's dual-issue data is properly protected when the shared data is processed.
  • the platform device end further includes a step S38 (not shown) for acquiring application desensitization data from the data application device through the development item according to the authorization information, wherein the application is desensitized The data is obtained by desensitizing the application production data in the data application device.
  • the data processing device is further configured to process the desensitization data and the application side desensitization data by the configured development item.
  • the platform device side obtains the desensitization data according to the authorization of the data application device, wherein the development project account including but not limited to the platform device obtains the access permission of the development project of the data application device side or the data application device sends the desensitization data to the device end
  • the development project of D company authorizes the development project of the third party, so that the desensitization data of the confidential data of D company can be separately or cooperated by the developer in the third-party development project.
  • the company's desensitization data is processed together, so that the confidential data of both parties in the third party is shared, and the third-party security management environment makes the data output need to be mutually permitted by both parties, thus protecting the data security.
  • the control based on the permission of the data in use makes the data provided by the business party invisible in the process of processing, that is, in the case that a business party needs to perform data processing, the business party secretly desensitizes the key features of the real data and
  • the process of providing the data developer with processing and finally processing the processing result is as follows.
  • FIG. 8 shows a schematic diagram of an apparatus for performing data processing in accordance with another aspect of the present application.
  • the data processing device includes a data desensitizing device 111, a desensitizing data transmitting device 112, and a desensitizing data processing device 113.
  • the data desensitizing device 111 in the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; the desensitization data transmitting device 112 sends the desensitization data to the corresponding development.
  • the desensitization data processing device 113 processes the desensitization data by the development project.
  • the data desensitizing device 111 in the data processing device desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the business hides the key sensitive features of the real data in the controlled security environment to obtain Retaining the necessary data features available to data users and hiding or eliminating them can cause security problems Data that senses the characteristics of the data.
  • the production data is the real data that the business party needs to process.
  • the production project is the security environment controlled by the business party. It can be created by the business party and has relevant control rights such as accessing data object permissions, user management and authorization rights, and resource creation.
  • business company A needs research institute B to develop software for data of an application, and can create a production project in a data development platform that can be used by both parties.
  • the created account is accessible to the owner of the production project.
  • the owner can assign a production account to have all the permissions except the security settings, so that the production account can develop an application for company A.
  • the real data is desensitized. Desensitize real data in a secure environment controlled by the business side, so that key security information of the data can be concealed to improve data security.
  • the desensitization data transmitting device 112 sends the desensitization data to the corresponding development project, which means sending the desensitized data to a security environment controlled by the data processing and controlling the data in a secure manner, for example, through a data platform of mutual trust.
  • the development project is a security environment that is trusted by the data provider for data processing by the data processing party.
  • the company A needs to perform software development processing on the data of an application in the data development platform. Create a production project and create a corresponding development project and assign development-related permissions such as creating tables, functions, resources, etc. in the development project to the development account of the B Institute, so that the desensitization data can be directly from the production project via the data development platform.
  • the manner of sending the desensitization data includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices, but is not limited thereto.
  • the desensitization data processing device 113 processes the desensitization data through the development project, which means that the data processor performs processing such as software development, data mapping, etc. on the desensitization data in a secure development project environment, but is not limited thereto. .
  • the account or role of the development project to deal with the desensitization data is assigned or created by the business party providing the data.
  • the company A creates the production project and the owner of the development project assigns the B research institute or the company personnel to the development project.
  • Administrator the administrator has access to all objects in the development project, and can manage and authorize the user or role, such as assigning the data developer of the B research institute to develop the account, and the development account has the permission to create the table or function. Therefore, the desensitization data provided by Company A can be developed, thereby facilitating the secure management of the development account, and making the development account available to the real data but not visible.
  • FIG. 9 shows a schematic diagram of an apparatus for performing data processing in accordance with another preferred embodiment of the present application.
  • the data processing device includes a data desensitizing device 211, a desensitizing data transmitting device 212, a desensitizing data processing device 213, a data processing result providing device 214, and a data processing result issuing device 215.
  • the data desensitizing device 211 in the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; the desensitization data transmitting device 212 sends the desensitization data to the corresponding development.
  • the desensitization data processing device 213 processes the desensitization data by the development project; the data processing result providing device 214 returns the processing result of the desensitization data in the development project to the production project; data processing The result issuing device 215 issues the processing result through the production item.
  • the data desensitizing device 211 and the desensitizing data processing device 213 are the same as or similar to the data desensitizing device 111 and the desensitizing data processing device 113 in FIG. 8 and will not be described again.
  • the data processing result providing means 214 in the data processing device returns the processing result of the desensitization data in the development item to the production item, which means that the processing result after the desensitization data is processed in the development item is returned.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception.
  • the developer of the B research institute sends the code to the production project through the data development platform after developing the software code of the application through the development account in the development project based on the desensitization data, so that the company A processes the data processing result. Review or evaluate to further ensure the security of data and data processing results.
  • the data processing result issuing device 215 issues the processing result through the production item, which means that the data provided by the data provider receives the returned desensitization data processing result in the production item, and then performs the code or the program on the data processing result through the real data.
  • Performance verification or external output is not limited to this.
  • the release processing result is to verify the data processing result or to produce it through real production data.
  • Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data to test the software program of the released data.
  • the data processing results are released in the production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
  • the data processing device further includes desensitization data authority setting means 216 (not shown) for setting authority information of the development item regarding the desensitization data. That is, after the production project desensitizes the real data, the same desensitization data may be used for more than one type of data processing, for example, software development, data analysis, etc., at this time, different uses of the data are different, so by setting Different permission information can be used differently for the desensitization data during development.
  • the data of the company A's desensitization data set during software development is read, created, etc., and the data analysis is only read-only.
  • the desensitizing data transmitting device 212 sending the desensitization data to the development project according to the authority information refers to selectively desensitizing data according to different rights regarding desensitization data open to a development project.
  • Sending to the development project, for example, Company A will need to perform desensitization data for a month of data analysis to send only desensitization data for the current month, while the desensitization data required for development software is one year or one quarter, thus making it take off
  • the transmission of sensitive data is more targeted and better manages the data.
  • FIG. 10 is a schematic diagram of an apparatus for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application.
  • the data providing device includes a data desensitizing device 311, a development authorization device 312, and a desensitization data transmitting device 313.
  • the data application device includes a desensitizing data acquiring device 321 and a desensitizing data processing device 322.
  • the data desensitizing device 311 desensitizes the production data in the production project to obtain corresponding desensitization data;
  • the development authorization device 312 develops and authorizes the application development project in the corresponding data application device through the development project;
  • the sensitive data transmitting device 313 sends the desensitized data to the application development project via the development project according to the result information of the development authorization process;
  • the desensitization data obtaining device 321 acquires the development from the data providing device through the application development project Desensitization data of the item, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
  • the desensitization data processing device 322 processes the desensitization data by the application development project.
  • the data desensitizing device 311 desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the data providing device side, that is, the data providing device end is sensitive to the real data in the controlled security environment.
  • the production project is a security environment controlled by the data provider business.
  • Company A cooperates with Company C to jointly develop an application software.
  • Company A provides key data for software development and is responsible for part of software development.
  • the company is responsible for software development. Therefore, in the data development platform, Company A creates a project space for the application, which is the data supply device.
  • the production project is the security environment for Company A to process real critical data, and the creation of owner A project space. Assigning the company's production account, the production account has all the rights except the security settings in the production project, that is, the data is desensitized in the production project before the company A provides the data, so that the key security information of the data can be Be concealed to improve data security.
  • the development authorization device 312 develops the authorization processing for the application development project in the corresponding data application device through the development project, which means that both the data providing device end and the data application device end have both the production project and the corresponding development project, because the production data is The real data should not be sent directly to different business parties from the security point of view. Therefore, after the data is desensitized, the desensitization data is sent to the development project of the project, and the development project of the data application device needs to obtain the desensitization data before using the desensitization data.
  • the data provides authorization for the business party represented by the device side.
  • the authorization method includes authorizing the development project to the data application device, so that it can be sent through the data development platform or through SFTP or other secure file transfer methods, but is not limited thereto, or the development account in the data application device development project is performed.
  • Authorization so that the development account can directly read the desensitization data in the data-providing device-side development project.
  • C company initiates the development and control of company A in the data development platform when it needs A company data for software development.
  • Company A authorizes the development account in the development project of Company C through the ACL authorization between the tables in the data development platform, so that the desensitization data can be safely transferred in the development environment.
  • the desensitization data transmitting device 313 sends the desensitization data to the application development project via the development project according to the result information of the development authorization process, and refers to the data providing device after the development project of the data application device end is authorized.
  • the terminal sends the desensitization data in the controlled development project to the development project on the data application device side.
  • the method of sending includes, but is not limited to, sending through a data development platform or developing a project in a data application device.
  • the development account is directly read according to the authorization, or is performed by SFTP or other secure file transmission method, but is not limited thereto.
  • the development account of Company C is read by the company A through the development project of the data providing device, and the desensitization data is read according to the authority, so that the desensitization data is visible and the production data is invisible, and the protection is guaranteed.
  • the security of real data during the data exchange process is guaranteed.
  • the desensitization data obtaining means 321 acquires desensitization data from the development item in the data providing device through the application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device, That is, as described above, after the data application device is authorized, the desensitization data provided by the data providing device development project is obtained according to the authorization, and the above example, that is, the development account in the development project in the project space created by the C company is controlled. After obtaining authorization, the desensitization data is read according to the authority.
  • the desensitization data processing device 322 processes the desensitization data by using the application development project, where the development project managed by the data application device processes the desensitization data after acquiring the desensitization data of the data providing device end.
  • the application development project is a data development environment controlled by the data application device end, and the business party where the data application device end is located controls the development authority, thereby effectively supervising the safe circulation of data, and the above example, that is, the data
  • the project space where C Company is located in the development platform utilizes the development account of the authorized C company in the development space to develop the desensitized data of the read company A, so as to achieve desensitization data when the business side performs non-confidential data exchange processing. Visible and invisible to real data.
  • the data application device side further includes a data desensitizing device 325 (not shown) for desensitizing the application production data in the application production project to obtain corresponding application desensitization data. That is, in the production project controlled by the data application device, the production data of the data application device can be desensitized to obtain the desensitization data of the data application device end.
  • the company A and the C company jointly carry out software development, C company While obtaining the desensitization data of Company A for development, combined with the real production data of Company C for software development, the data is desensitized in the production project of Company C controlled by the data development platform, thereby obtaining the company C. Desensitization data.
  • the desensitization data processing device 322 is further configured to process the desensitization data and the application desensitization data by using the application development project, that is, the data application device-side development project obtains its corresponding data application device.
  • the desensitization data provided in the end production project is processed and processed.
  • the above example that is, the development project of C company in the data development platform develops the desensitization data of the real data of the C company provided by the C company production project. Processing, so that A and C companies in the joint development process, C company can combine the desensitization data of both parties for processing and can ensure the security of real data in the process of circulation.
  • FIG. 11 shows a schematic diagram of a device for performing data processing, which is implemented by a data providing device end and a data application device end according to another preferred embodiment of the present application, wherein the data providing device The end includes a data desensitizing device 411, a development authorization device 412, and a desensitization data transmitting device 413; the data application device end includes desensitization data acquiring device 421 and desensitization data processing device 422; data processing result providing device 423; data processing The result is published 424.
  • the data providing device The end includes a data desensitizing device 411, a development authorization device 412, and a desensitization data transmitting device 413;
  • the data application device end includes desensitization data acquiring device 421 and desensitization data processing device 422; data processing result providing device 423; data processing The result is published 424.
  • the data desensitizing device 411 desensitizes the production data in the production project to obtain corresponding desensitization data; and the development authorization device 412 develops and authorizes the application development project in the corresponding data application device through the development project;
  • the sensitive data transmitting device 413 sends the desensitized data to the application development project via the development project according to the result information of the development authorization process;
  • the desensitization data acquiring device 421 acquires the development from the data providing device through the application development project Desensitization data of the item, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
  • the desensitization data processing device 422 processes the desensitization data by the application development project;
  • the data processing result providing means 423 supplies the processing result of the desensitization data in the application development item to the application production item;
  • the data processing result issuing means 424 issues the processing result through the application production item.
  • the data desensitizing device 411, the development authorizing device 412, the desensitizing data transmitting device 413, the desensitizing data acquiring device 421, and the desensitizing data processing device 422 are the same as the data desensitizing device 311 and the development authorizing device 312 in FIG.
  • the desensitization data transmitting device 313, the desensitizing data acquiring device 321, and the desensitizing data processing device 322 are the same or similar and will not be described again.
  • the data processing result providing means 423 in the data application device side provides the processing result of the desensitization data in the application development project to the application production item, and refers to the data providing device in the development project of the data application device side
  • the processed result of the desensitization data provided by the terminal is returned to the production project controlled by the data application device.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception.
  • the developer of Company C develops the software code of the application through the development account in the development project based on the desensitization data, and then sends the code to the production project of the C company through the data development platform, so that the company C is united.
  • the data processing results developed are uniformly reviewed or evaluated to further ensure the security of data and data processing results.
  • the data processing result issuing device 424 issues the processing result through the application production item, which means that the data application device receives the returned desensitization data processing result in the production project, and then performs the code or the program on the data processing result through the real data.
  • Performance verification or external output is not limited to this.
  • the release processing result is to verify the data processing result or to obtain the data providing device end device in the production project after the authorization of the data on the data application device, and then to produce the data based on the real production data.
  • Company C returns to the production project.
  • the program code based on the desensitization data development of company A is released on the data development platform, and the production account uses the real data authorized by company A to test the software program of the released data.
  • the data processing result is released in the production space, so that the processing result is post-processed or verified in the security environment of the data provider, so that the company A and the C company cooperate in the process of data processing, and the development project authorizes the development project so that C
  • the company's development account can read the company's desensitization data, so that the development process has targeted protection and development of data permissions, development projects to improve the security of data processing results.
  • the data providing device end further includes a production authorization device 414 (not shown) for performing production authorization processing on the application production item in the data application device by the production item; and the production data transmitting device 415 ( Not shown) for transmitting the production data to the application production item via the production item according to result information of the production authorization process.
  • the data application device side further includes a production data acquisition device 426 (not shown) for acquiring production data of the production items in the data providing device by applying the production item.
  • the production authorization device 414 (not shown) performs production authorization processing on the application production item in the data application device by the production item, that is, the controlled production item of the data providing device end is read by the authorized account.
  • Data, etc. authorize production projects on the data application device side.
  • the authorization method includes, but is not limited to, the production project management account in the data providing device side, so that the management account of the data application device side production space can read the production data in the data providing device end by means of the access control between the tables, and the like.
  • the production account of the production project in the project space controlled by Company A authorizes the production account of the production project in the project space controlled by Company C, so that it can obtain the authority to read the real production data, thereby completing the authorization.
  • a production data transmitting device 415 for transmitting the production data to the application production item via the production item according to the result information of the production authorization process means authorizing information according to the data providing device side
  • the production data is sent to the controlled production project of the data application device side.
  • the authorized production data of the company A is sent to the C.
  • the reading authority of the production data of company A is obtained to read the production data of company A.
  • a production data obtaining means 426 (not shown) for acquiring production data of the production item in the data providing device by applying the production item, wherein the data processing result issuing means 423 is based on the production data
  • the execution result of the processing in the application production project refers to that after the data application device obtains the production data of the data providing device according to the authorization, after obtaining the processing result obtained based on the desensitization data of the data providing device on the controlled production item, the data is passed.
  • the executing party The formula includes, but is not limited to, code or program performance verification or external output through real data.
  • the company C releases the desensitization data based on the company A through the production account in the controlled production project.
  • the obtained software code is tested or tested by the production data provided by Company A to Company C, so that the production data is only distributed in the production project environment of A and C companies.
  • the desensitization data is only in A and C companies.
  • the circulation in the development environment ensures that when the data development process is jointly performed, only the business party can see the real data, but the developer only sees the desensitization data, thereby improving the security of the data during non-confidential exchange.
  • the different business parties are secured in the process of confidential data exchange and processing, that is, the business side providing data to the two parties in the business involved in the confidential data exchange entrusts the data to the mutual trust security.
  • the data processing business side adds the developer authorization to the third party for data processing, thus ensuring the effect that the confidential data is available but not replicable in a secure management environment, as follows.
  • FIG. 12 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application.
  • the data providing device includes a data desensitizing device 511 and a desensitizing data transmitting device 512.
  • the data application device includes a platform configuration device 521.
  • the platform device includes a desensitizing data acquiring device 531, a configuration device 532, and a desensitizing data processing device. 533.
  • the data desensitizing device 511 in the data providing device performs desensitization processing on the production data in the data providing device to obtain corresponding desensitization data; the desensitizing data transmitting device 512 transmits the desensitized data to the corresponding platform.
  • the device is processed by the corresponding data application device; the desensitization data obtaining device 531 in the platform device end acquires desensitization data from the data providing device, wherein the desensitization data is desensitized by the production data in the data providing device
  • the data acquisition device platform configuration device 521 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
  • the platform device end configuration device 532 is configured according to The platform device is configured to correspond to the data application device; the desensitization data processing device 533 processes the desensitization data through the configured platform device.
  • the data desensitizing device 511 in the data providing device desensitizes the production data in the data providing device to obtain the corresponding desensitized data, which means that the data providing device is sensitive to the real data at the data providing device end.
  • the concealment of features results in data that retains the necessary data features available to the data consumer and conceals or eliminates data characteristics that would result in security-sensitive data.
  • production data refers to real data containing key sensitive features.
  • Data desensitization methods include, but are not limited to, desensitization directly on the data development platform or through manual screening. For example, Company A and Company D have certain types of data.
  • the desensitizing data sending device 512 sends the desensitized data to the corresponding platform device for processing by the corresponding data application device, and means sending the desensitized data to the data processing device end and the data providing device end at the data providing device end.
  • the third-party data processing platform device side trusted by the represented business parties enables the data application device side to perform data processing in the third-party platform.
  • the corresponding platform device refers to a third-party data processing platform that is trusted by both parties of the data flow, such as a data processing space or platform project that can jointly create related data processing permissions, but is not limited thereto.
  • Company A and Company D jointly entrust a third party as the control and arbitration party in the exchange process.
  • the third party supervises a project space and performs security settings.
  • Company A sends desensitization data to the first
  • the project space controlled by the three parties is for the company D to process it in a third party.
  • the method of sending the desensitization data may be directly transmitted in the background through the data development platform or transmitted through a related protocol for secure transmission of the encrypted file, but is not limited thereto.
  • the desensitization data acquisition means 531 in the platform device side acquires desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  • the platform device side is used as a data providing device and a security environment controlled by a third party trusted by the data application device end, and accepts or acquires the desensitization data of the data providing device end under a certain authority, thereby facilitating the data application device end.
  • the project space created by the third party in the data platform is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A.
  • the company's desensitization data is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A.
  • the platform configuration device 521 in the data application device configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. That is, the data application device side performs the direct authorization of the development account or the project space package authorization on the platform device side, so that the data application device can process the desensitization data in the security environment controlled by the platform set end, For example, Company D authorizes the project space controlled by third parties in the data development platform, so that developers of Company D can process the data in the third-party project space.
  • the method for configuring the platform device may be to directly authorize the project space controlled by the platform or authorize the development-related account in the platform, so that the data application device can perform data processing through the account, but is not limited thereto.
  • the platform device configuration device 532 configures the platform device according to the corresponding data application device.
  • the platform device device is configured according to the data application device end, so that the data application device terminal can process the desensitization data in a security environment controlled by the platform device.
  • the manner in which the platform device is configured according to the corresponding data application device includes but is not limited to The development account of the authorization data application device can perform data processing in the project space controlled by the platform device or the data application device directly performs authorization processing on the platform device end.
  • the platform device is configured to enable the data application device to process the desensitized data in the security management environment during the confidential data exchange, thereby improving the security of the confidential data.
  • the desensitization data processing device 533 processes the desensitization data by using the configured platform device, and the data application device end desensitizes the data according to the authority of the device platform in the third-party security environment controlled by the platform device.
  • a and D companies authorized the third-party project space in the data development platform, and then added the developer of the D company to the third-party project space for data processing, so that the data application device can be used.
  • Data provides confidential data on the device side, and at the same time, confidential data cannot be copied in a secure third-party environment, thereby improving the security of confidential data during use and processing.
  • FIG. 13 is a schematic diagram of a platform device end in a device for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
  • the platform device end includes a platform item creation device 634, a desensitization data acquisition device 631, a configuration device 632, and a desensitization data processing device 633.
  • the platform item creation device 634 in the platform device side creates an item in the platform device;
  • the desensitization data obtaining device 631 acquires desensitization data from the data providing device through the item, wherein the desensitization data Obtained by the desensitization process of the production data in the data providing device;
  • the configuration device 632 configures the item according to the corresponding data application device;
  • the desensitization data processing device 633 processes the desensitization data through the configured item.
  • the platform item creation device 634 in the platform device side creates a project in the platform device, which means creating a secure data flow and processing space in the platform device trusted by the data providing device end and the data application device end, so that the confidential data is made. You can receive protection in a secure project space.
  • Company A and Company D jointly commission a data development platform or a third party trusted by both parties to create a secure project space in the data development platform. So that A and D companies can process and share data in the project space.
  • the desensitization data acquiring means 631 acquires desensitization data from the data providing device by the item, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  • the project space created by the platform device side obtains desensitization data in the data providing device side by directly authorizing the project space of the data providing device side.
  • Company A is in the data development platform to the third party. The project space is authorized so that the desensitization data can only be accessed in the third-party project space, thereby limiting the circulation and processing range of the confidential data, thereby improving the security of the data.
  • the configuration device 632 configures the item according to the corresponding data application device, that is, the platform device side sets the project space according to the authorization of the data application device end.
  • the third-party project space obtains the authorization of the project space of the D company.
  • the developers of Company D are added, so that the developers of Company D can process the desensitization data of Company A in the third-party project space.
  • the desensitization data processing device 633 processes the desensitization data through the configured item, that is, the developer or the account of the data application device side is configured, and then the platform device end pairs the data in the controlled project space.
  • the desensitization data provided by the device is provided for processing.
  • the desensitization data of the confidential data provided by the company A is processed in the third-party project space, thereby Limiting the flow of confidential data to the project space further enhances the security of confidential data.
  • FIG. 14 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
  • the data providing device end includes a data desensitizing device 711, a platform authorization device 713, and a desensitization data transmitting device 712;
  • the data application device end includes a configuration device 721;
  • the platform device end includes a platform item creating device 734,
  • the platform item creation means 734 creates an item in the platform device; the data desensitization means 711 desensitizes the production data in the data providing device to obtain corresponding desensitization data; the platform authorization means 713 pairs the platform The item in the device performs authorization processing; the authorization obtaining device 735 acquires authorization information of the data providing device and the data application device for the item; the desensitization data transmitting device 712 sends the desensitization data to the corresponding platform device For the corresponding data application device to process; the desensitization data obtaining device 731 acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data passes through the data providing device The production data desensitization process is obtained; the platform configuration device 721 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; 732 configuring the item according to the corresponding data
  • the data desensitizing device 711, the desensitizing data transmitting device 712, and the platform arranging device 721 are the same as or similar to the data desensitizing device 511, the desensitizing data transmitting device 512, and the platform arranging device 521 in FIG.
  • the platform project creation device 734 is the same as or similar to the platform project creation device 634 in FIG. 13 and will not be described again.
  • Authorizing the item in the platform device by the platform authorization device 713 in the data providing device refers to authorizing the project space controlled by the trusted platform device at the data providing device end.
  • the authorization method can directly package and authorize the platform device item through the item in the data providing device, so that the confidential data provided by the data providing device end can be obtained by the platform device item, and the above example is in the data.
  • the project space of Company A in the development platform packages and authorizes the third-party project space, so that the account of the third-party project space can read the desensitization data or the third-party project space has the right to accept desensitization data.
  • the authorization obtaining device 735 in the platform device end obtains the authorization information of the data providing device and the data application device for the item, and refers to the authorization of the data providing device end and the data application device end of the platform device end. Therefore, the flow and processing of confidential data are transferred in a secure environment of mutual trust.
  • the project space of company A and company D packages and authorizes the third-party project space, thereby making company A Desensitization data can be streamed in third-party project spaces and developers of Company D can develop desensitization data for Company A in a third-party space. Data is transferred and processed in a secure and controllable environment through project authorization on the platform device side to improve data security.
  • the desensitization data obtaining means 731 in the platform device end acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data is passed through the data providing device Production data desensitization is obtained. That is, the project on the platform device side obtains the desensitization data according to the authorization of the data providing device end, wherein the obtaining manner includes, but is not limited to, reading the desensitized data within the authority according to the authorization of the project, In the data development platform, Company A grants the third-party project the right to read and copy the desensitized data of the confidential data, so that the third-party project acquires the desensitization data of Company A.
  • the items in the data providing device, the data application device, and the platform device include a production project and a development project.
  • the production project refers to a project space in the project that processes real data, and is controlled by each business party;
  • the development project is Refers to the project space where the developer handles the desensitization data in the project, and is used by the development account assigned by the business party.
  • the authorization obtaining device 735 of the platform device end is further configured to acquire authorization information of the data providing device and the data application device for the production item. That is, the production project on the data development device side and the data application device side package and authorize the production items in the platform device side of the common trust, so that the real data to be processed within the allowable range of the two can be shared in a safe production project environment.
  • Company A and Company D authorize the production projects in the third-party projects in the data development platform, and obtain the real data required by the two parties to jointly develop the software after obtaining the authorization.
  • the desensitization data obtaining device 731 in the platform device end is further configured to acquire desensitization data from the data providing device by using the development item according to the authorization information, wherein the desensitization data passes the The production data desensitization process in the data providing device is obtained.
  • the desensitization data in the platform device is provided by the data providing device side to the desalination data to the development project that can be used only by the data application device developer, and according to the above example, according to the authorization of the company A for the third party data,
  • the third-party development project obtains the desensitization data of Company A, so that the developer who adds the developer to the third-party development project can process and use the desensitization data of Company A through the development project, thereby ensuring that the desensitization data can be It is used by developers of Company D in a third-party security environment, but because the desensitized data cannot be copied or reserved for use in a third-party controlled environment, the security of confidential data is guaranteed.
  • the platform device end configuration device 732 is further configured to configure the development project according to the corresponding data application device. That is, the data application device can process the desensitization data provided by the data providing device in the platform device by adding the development account in the data application device to the development project or the like through the platform device end.
  • the development project space shared by A and D companies in the data development platform adds the developer account of Company D to the project space of the third party according to the application of Company D, and then processes the desensitization data of Company A.
  • the desensitization data processing device 733 in the platform device end is further configured to process the desensitization data through the configured development item.
  • the desensitization data provided by the data providing device is processed in the development project of the platform device side, and the developer of the D company in the data development platform is connected as an example.
  • the account number is added to the development of the desensitization data of Company A in the third-party development project space, so that the desensitization data cannot be copied or reserved for use in a third-party controlled environment, and the confidential data is guaranteed. Security.
  • the data processing result providing means 736 in the platform device side provides the processing result of the desensitization data in the application development project to the application production item.
  • desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like.
  • the return method of desensitization data processing results includes However, it is not limited to the background system of the data development platform or the establishment of a secure channel such as SFTP between the computer devices for transmission and reception.
  • the developer of Company D develops the software code of the application through the development account in the third-party development project based on the desensitization data, and then sends the code back to the production project through the data development platform, so that Company A is in the third party.
  • Data processing results are reviewed or evaluated in the production project space to further ensure the security of data and data processing results.
  • the data processing result issuing means 737 in the platform set end issues the processing result of the desensitizing data in the development item through the production item.
  • the release processing result is to verify the data processing result or to produce it through real production data.
  • Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data in the third-party project space to execute the software program on the released data. Test work.
  • the data processing results are released in the third-party production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
  • the data application device side further includes a platform authorization device 722 (not shown) for performing authorization processing on the items in the platform device. That is, the data application device uses the data to provide the data of the device end, and in the case that the data needs to be processed together with the data, the platform can be authorized to obtain the data to apply the confidential data of the device or the desensitization data thereof.
  • a platform authorization device 722 for performing authorization processing on the items in the platform device. That is, the data application device uses the data to provide the data of the device end, and in the case that the data needs to be processed together with the data, the platform can be authorized to obtain the data to apply the confidential data of the device or the desensitization data thereof.
  • D company needs to combine the confidential data of Company D with the desensitization data of Company A to develop or research the software in the third-party development environment. Therefore, the project space controlled by Company D is the first.
  • the three-party platform project is authorized to provide desensitization data of D company's confidential data, so that
  • the platform device side further includes an application-side desensitization data acquisition device 738 (not shown) for acquiring application-side desensitization data from the data application device through the development project according to the authorization information, where The application desensitization data is obtained by desensitizing the application side production data in the data application device.
  • the desensitization data processing device 733 is further configured to process the desensitization data and the application side desensitization data through the configured development item.
  • the platform device side obtains the desensitization data according to the authorization of the data application device, wherein the development project account including but not limited to the platform device obtains the access permission of the development project of the data application device side or the data application device sends the desensitization data to the device end
  • the development project of D company authorizes the development project of the third party, so that the desensitization data of the confidential data of D company can be separately or cooperated by the developer in the third-party development project.
  • the company's desensitization data is processed together, so that the confidential data of both parties in the third party is shared, and the third-party security management environment makes the data output need to be shared by both parties. Same as allowed, thus protecting the security of the data.

Abstract

Provided are a method and device for data processing. The method specifically comprises: at a data providing device end, performing desensitization processing on production data in a data providing device to obtain corresponding desensitization data (S11); at a platform device end, obtaining the desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device (S31); configuring a platform device according to a corresponding data application device (S32); processing the desensitization data via the configured platform device (S33). Compared with the prior art, by means of performing third party assurance on data security depending on a data exchange and use platform, the problems of data being required to be available but invisible when different service parties exchange confidential data and use same and the assurance of data security are solved, so that the data is placed in a third-party secure environment for circulation and use in the case where a data providing party and use party are not fully trusted by each other, thereby guaranteeing the security of the data in circulation and use.

Description

一种用于数据处理的方法和设备Method and device for data processing
本申请要求2015年08月10日递交的申请号为201510486640.2、发明名称为“一种用于数据处理的方法和设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。The present application claims priority to Chinese Patent Application Serial No. No. No. No. No. No. No. No. No. No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No No
技术领域Technical field
本申请涉及计算机领域,尤其涉及一种用于数据处理技术。The present application relates to the field of computers, and in particular to a technique for data processing.
背景技术Background technique
随着大数据时代的来临,数据的使用及交换日益频繁,然而数据提供与使用往往会涉及不完全信任的业务双方,现有技术会通过向数据使用方提供抽样过的脱敏样本数据使得数据不可见,或者对数据使用方的数据使用相关权限进行限制。With the advent of the era of big data, the use and exchange of data is increasingly frequent. However, the provision and use of data often involves both parties to the business that are not fully trusted. The prior art will make the data by providing sampled desensitized sample data to the data user. Not visible, or restricted to the data consumer's data using the relevant permissions.
然而,现有技术因为无法准确控制使用方对数据的处理过程和环境,例如授权阶段对可见数据进行复制,或者数据抽样脱敏过程不够灵活以及数据提供方对使用方数据使用环境不信任等问题,因此导致使用数据与不允许数据使用方看到或导出数据的矛盾逐渐凸显。However, the prior art cannot accurately control the processing process and environment of the data by the user, such as copying the visible data in the authorization phase, or the data sampling desensitization process is not flexible enough, and the data provider does not trust the usage data usage environment. Therefore, the contradiction between using the data and not allowing the data consumer to see or export the data is gradually highlighted.
发明内容Summary of the invention
本申请的目的是提供一种用于数据处理的方法与设备,用以解决数据使用过程中需要数据可用不可见以及进行机密或非机密数据交换时保障数据安全的问题。The purpose of the present application is to provide a method and device for data processing, which is to solve the problem that data needs to be invisible during data usage and data security is ensured when confidential or non-confidential data exchange is performed.
根据本申请的一个方面,提供了一种用于进行数据处理的方法,该方法解决了业务方在数据使用过程中需要数据可用不可见的问题,该方法包括:According to an aspect of the present application, a method for data processing is provided, which solves the problem that a service party needs data to be invisible during data usage, and the method includes:
对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;Desensitizing the production data in the production project to obtain corresponding desensitization data;
将所述脱敏数据发送至对应的开发项目;Sending the desensitization data to a corresponding development project;
通过所述开发项目处理所述脱敏数据。The desensitization data is processed by the development project.
根据本申请的另一个方面,提供了一种由数据提供设备端以及数据应用设备端配合使用从而进行数据处理的方法,该方法解决了不同业务方非机密数据交换使用时需要数据可用不可见的问题,该方法包括:According to another aspect of the present application, a method for data processing by using a data providing device end and a data application device end is provided, which solves the problem that data needs to be invisible when different business parties use non-confidential data exchange. Problem, the method includes:
在数据提供设备端,对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;At the data providing device end, the production data in the production project is desensitized to obtain corresponding desensitization data;
在数据提供设备端,通过开发项目对对应数据应用设备中的应用开发项目进行开发 授权处理;On the data providing device side, develop the application development project in the corresponding data application device through the development project. Authorization processing;
在数据提供设备端,根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目。At the data providing device side, the desensitization data is sent to the application development project via the development project according to result information of the development authorization process.
在数据应用设备端,通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;On the data application device side, desensitization data from a development item in the data providing device is obtained by an application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
在数据应用设备端,通过所述应用开发项目处理所述脱敏数据。At the data application device side, the desensitization data is processed by the application development project.
根据本申请的再一个方面,提供了一种由数据提供设备端、数据应用设备端在平台设备端配合使用从而进行数据处理的方法,该方法解决了不同业务方进行机密数据交换以及使用时需要数据可用不可见以及保障数据安全的问题,该方法包括:According to still another aspect of the present application, a method for data processing by a data providing device end and a data application device end for use in a platform device end is provided, which solves the problem that different business parties perform confidential data exchange and use. Data is invisible and data security is guaranteed. This method includes:
在数据提供设备端,对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;At the data providing device end, desensitizing the production data in the data providing device to obtain corresponding desensitization data;
在数据提供设备端,将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;Sending, on the data providing device end, the desensitization data to a corresponding platform device for processing by the corresponding data application device;
在数据应用设备端,配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;At the data application device side, the platform device is configured to process desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
在平台设备端,获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Acquiring desensitization data from the data providing device on the platform device side, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
在平台设备端,根据对应数据应用设备配置平台设备;On the platform device side, configure the platform device according to the corresponding data application device;
在平台设备端,通过配置后的所述平台设备处理所述脱敏数据。At the platform device end, the desensitization data is processed by the configured platform device.
根据本申请的另一个方面,,提供了一种用于进行数据处理的设备,该设备解决了业务方在数据使用过程中需要数据可用不可见的问题,该设备包括:According to another aspect of the present application, there is provided an apparatus for performing data processing, which solves the problem that a service party needs data invisibility to be invisible during data use, and the apparatus includes:
数据脱敏装置,用于对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;a data desensitizing device for desensitizing the production data in the production project to obtain corresponding desensitization data;
脱敏数据发送装置,用于将所述脱敏数据发送至对应的开发项目;a desensitization data transmitting device, configured to send the desensitization data to a corresponding development project;
脱敏数据处理装置,用于通过所述开发项目处理所述脱敏数据。A desensitization data processing device for processing the desensitization data by the development project.
根据本申请的另一个方面,提供了一种由数据提供设备端以及数据应用设备端配合使用从而进行数据处理的设备,该设备解决了不同业务方非机密数据交换使用时需要数据可用不可见的问题,该设备包括:According to another aspect of the present application, an apparatus for data processing is used by a data providing device end and a data application device end, and the device solves the problem that different data is invisible when non-confidential data exchange is used by different service parties. Problem, the device includes:
数据提供设备端的数据脱敏装置,用于对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;The data providing device data desensitizing device is configured to desensitize the production data in the production project to obtain corresponding desensitization data;
数据提供设备端的开发授权装置,用于通过开发项目对对应数据应用设备中的应用 开发项目进行开发授权处理;The data providing device development development authorization device is used for the application in the corresponding data application device through the development project Development project for development authorization processing;
数据提供设备端的脱敏数据发送装置,用于根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目;a desensitizing data transmitting device of the data providing device, configured to send the desensitizing data to the application development project via the development project according to result information of the development authorization process;
数据应用设备端的脱敏数据获取装置,用于通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;a desensitization data acquisition device on the data application device side for acquiring desensitization data from a development item in the data providing device through an application development project, wherein the desensitization data is obtained by taking production data of a production item in the data providing device Sensitive treatment obtained;
数据应用设备端的脱敏数据处理装置,用于通过所述应用开发项目处理所述脱敏数据。A desensitizing data processing device on the data application device side for processing the desensitization data by the application development project.
根据本申请的再一个方面,提供了一种由数据提供设备端、数据应用设备端在平台设备端配合使用从而进行数据处理的设备,该设备解决了不同业务方进行机密数据交换以及使用时需要数据可用不可见以及保障数据安全的问题,该设备包括:According to still another aspect of the present application, an apparatus for data processing by using a data providing device end and a data application device end on a platform device end is provided, and the device solves the problem that different business parties perform confidential data exchange and use. Data is invisible and data security is guaranteed. The device includes:
数据提供设备端的数据脱敏装置,用于对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;The data providing device data desensitizing device is configured to desensitize the production data in the data providing device to obtain corresponding desensitization data;
数据提供设备端的脱敏数据发送装置,用于将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;The data providing device desensitizing data sending device is configured to send the desensitizing data to a corresponding platform device for processing by a corresponding data application device;
数据应用设备端的平台配置装置,用于配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;a platform configuration device of the data application device, configured to configure the platform device to process desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
平台设备端的脱敏数据获取装置,用于获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;a desensitization data acquiring device on the platform device side for acquiring desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
平台设备端的配置装置,用于根据对应数据应用设备配置平台设备;a device device configured on the platform device, configured to configure the platform device according to the corresponding data application device;
平台设备端的脱敏数据处理装置,用于通过配置后的所述平台设备处理所述脱敏数据。The desensitization data processing device on the platform device side is configured to process the desensitization data by using the configured platform device.
与现有技术相比,本申请的一个实施例在数据提供设备端对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;在平台设备端获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;根据对应数据应用设备配置平台设备;通过配置后的所述平台设备处理所述脱敏数据,解决了不同业务方进行机密数据交换以及使用时需要数据可用不可见以及保障数据安全的问题,从而在数据提供方与使用方不完全信任的情况将数据置入第三方安全环境中进行流转和使用,保证了数据在流转和使用中的安全。 Compared with the prior art, an embodiment of the present application desensitizes the production data in the data providing device at the data providing device end to obtain corresponding desensitization data; and acquires desensitization from the data providing device at the platform device end. Data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; configuring the platform device according to the corresponding data application device; processing the desensitization data through the configured platform device to solve The problem of confidential data exchange and the invisibility of data availability and data security when using different business parties, so that data is placed in a third-party security environment for circulation and use when the data provider and the user do not fully trust. It ensures the security of data flow and use.
附图说明DRAWINGS
通过阅读参照以下附图所作的对非限制性实施例所作的详细描述,本申请的其它特征、目的和优点将会变得更明显:Other features, objects, and advantages of the present application will become more apparent from the detailed description of the accompanying drawings.
图1示出根据本申请一个方面的用于进行数据处理的方法流程图;1 shows a flow chart of a method for performing data processing in accordance with an aspect of the present application;
图2示出根据本申请一个优选实例的用于进行数据处理的方法流程图;2 shows a flow chart of a method for performing data processing in accordance with a preferred embodiment of the present application;
图3示出根据本申请另一个方面的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的方法流程图;3 is a flowchart of a method for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application;
图4示出示出根据本申请另一个优选实例的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的方法流程图;4 is a flow chart showing a method for performing data processing according to another embodiment of the data providing device and the data application device according to another preferred example of the present application;
图5示出根据本申请另一个方面的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法流程图;FIG. 5 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application;
图6示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法中平台设备端方法流程图;6 is a flowchart of a platform device-side method in a method for implementing data processing, which is implemented by a data providing device end, a data application device end, and a platform device end according to another preferred example of the present application;
图7示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法流程图;FIG. 7 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred example of the present application;
图8示出根据本申请另一个方面的用于进行数据处理的设备示意图;8 shows a schematic diagram of an apparatus for performing data processing in accordance with another aspect of the present application;
图9示出根据本申请另一个优选实例的用于进行数据处理的设备示意图;FIG. 9 is a schematic diagram of an apparatus for performing data processing according to another preferred embodiment of the present application; FIG.
图10示出根据本申请另一个方面的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的设备示意图;FIG. 10 is a schematic diagram of an apparatus for performing data processing according to a data providing device end and a data application device end according to another aspect of the present application; FIG.
图11示出示出根据本申请另一个优选实例的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的设备示意图;11 is a schematic diagram showing an apparatus for performing data processing, which is implemented by a data providing device end and a data application device end according to another preferred example of the present application;
图12示出根据本申请另一个方面的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备示意图;FIG. 12 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application;
图13示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备中平台设备端示意图;13 is a schematic diagram of a platform device end in a device for implementing data processing, which is implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application;
图14示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备示意图。FIG. 14 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application.
附图中相同或相似的附图标记代表相同或相似的部件。The same or similar reference numerals in the drawings denote the same or similar components.
具体实施方式 detailed description
下面结合附图对本申请作进一步详细描述。The present application is further described in detail below with reference to the accompanying drawings.
在本申请一个典型的配置中,终端、服务网络的设备和可信方均包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。In a typical configuration of the present application, the terminal, the device of the service network, and the trusted party each include one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。The memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory. Memory is an example of a computer readable medium.
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括非暂存电脑可读媒体(transitory media),如调制的数据信号和载波。Computer readable media includes both permanent and non-persistent, removable and non-removable media. Information storage can be implemented by any method or technology. The information can be computer readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, A magnetic tape cartridge, magnetic tape storage or other magnetic storage device or any other non-transportable medium that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include non-transitory computer readable media, such as modulated data signals and carrier waves.
本申请包含三种数据处理的情况,其一基于数据使用中权限的控制使得业务方所提供的数据在处理过程中可用不可见;其二基于授权方式使得不同业务方在非机密数据交换的过程中安全流通且同样可用不可见;其三基于委托第三方平台的方式使得不同业务方的在机密数据交换及处理过程中得到安全保障。The present application includes three cases of data processing, one of which is based on the control of the rights in the data use, so that the data provided by the business party is invisible in the process; and the second is based on the authorization mode, so that different business parties are in the process of non-confidential data exchange. The medium-sized security circulation is also invisible; the third is based on the way of entrusting a third-party platform to ensure the security of different business parties in the process of confidential data exchange and processing.
基于数据使用中权限的控制使得业务方所提供的数据在处理过程中可用不可见的情况,即在一个业务方需要进行数据处理的情况下,业务方对真实数据的关键特征进行隐匿脱敏并提供给数据开发方进行处理,最终再将处理结果进行处理的过程,具体如下。The control based on the permission of the data in use makes the data provided by the business party invisible in the process of processing, that is, in the case that a business party needs to perform data processing, the business party secretly desensitizes the key features of the real data and The process of providing the data developer with processing and finally processing the processing result is as follows.
图1示出根据本申请一个方面的用于进行数据处理的方法流程图。其中,所述数据处理设备包括步骤S11、步骤S12以及步骤S13。1 shows a flow chart of a method for performing data processing in accordance with an aspect of the present application. The data processing device includes step S11, step S12, and step S13.
具体地,在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;在步骤S12中数据处理设备将所述脱敏数据发送至对应的开发项目;在步骤S13中数据处理设备通过所述开发项目处理所述脱敏数据。Specifically, in step S11, the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding development project; The data processing device processes the desensitization data through the development project in step S13.
在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据是指业务在所管控的安全环境中对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会致使安全问题敏感数据特征 的数据。其中,生产数据即为业务方需要处理的真实数据,生产项目即为业务方所管控的安全环境,可由业务方进行创建并掌相关控制权限如访问数据对象权限、用户管理和授权权限、资源创建等,例如,业务方A公司需要研究所B对某种应用的数据进行软件开发,可在某双方均可使用的数据开发平台中创建生产项目,该创建的账号即为生产项目的owner可访问生产项目中的所有资源并对用户或账号进行授权以及设置生产项目的安全设置,owner可指派一个生产账号使得其拥有除安全设置之外的全部权限,从而生产账号可以对A公司开发某应用软件的真实数据进行脱敏处理。在业务方管控的安全环境中对真实数据进行脱敏,使得数据的关键安全信息得以被隐匿从而提升数据的安全保障。In step S11, the data processing device desensitizes the production data in the production project to obtain corresponding desensitization data, which means that the service hides the key sensitive features of the real data in the controlled security environment, thereby obtaining the reserved The necessary data characteristics used by the data user hide or eliminate the data characteristics that would cause security issues to be sensitive The data. The production data is the real data that the business party needs to process. The production project is the security environment controlled by the business party. It can be created by the business party and has relevant control rights such as accessing data object permissions, user management and authorization rights, and resource creation. For example, business company A needs research institute B to develop software for data of an application, and can create a production project in a data development platform that can be used by both parties. The created account is accessible to the owner of the production project. Produce all the resources in the project and authorize the user or account and set the security settings of the production project. The owner can assign a production account to have all the permissions except the security settings, so that the production account can develop an application for company A. The real data is desensitized. Desensitize real data in a secure environment controlled by the business side, so that key security information of the data can be concealed to improve data security.
本领域技术人员应能理解上述获取脱敏数据的方式仅为举例,其他现有的或今后可能出现的获取脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should understand that the above manner of obtaining desensitization data is only an example, and other existing or future possible methods for obtaining desensitization data may be applicable to the present application, and should also be included in the scope of protection of the present application. It is hereby incorporated by reference.
接着,在步骤S12中数据处理设备将所述脱敏数据发送至对应的开发项目是指通过安全的方式例如通过共同信任的数据开发平台将脱敏数据发送至使用和处理数据方所管控的安全环境中。其中,所述开发项目即为数据提供方所信任的由数据处理方进行数据处理的安全环境,接上文举例,A公司在需要对某应用的数据进行软件开发处理时,在数据开发平台中创建生产项目的同时创建相应的开发项目并将开发项目中的开发相关权限如创建表、函数、资源等权限赋予B研究所的开发账号,从而可经由数据开发平台直接将脱敏数据从生产项目发送至开发项目中。发送脱敏数据的方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收,但并不限于此。将脱敏数据发送至数据提供业务方所信任的安全开发项目环境中,可提升数据开发过程中的安全可控性。Then, in step S12, the data processing device sends the desensitization data to the corresponding development project, which means that the desensitization data is sent to the security of the data processing and control by the data development platform, for example, through a common trust data development platform. Environment. The development project is a security environment that is trusted by the data provider for data processing by the data processing party. In the above example, the company A needs to perform software development processing on the data of an application in the data development platform. Create a production project and create a corresponding development project and assign development-related permissions such as creating tables, functions, resources, etc. in the development project to the development account of the B Institute, so that the desensitization data can be directly from the production project via the data development platform. Send to the development project. The manner of sending the desensitization data includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices, but is not limited thereto. Send desensitized data to the security development project environment trusted by the data provider to improve security and controllability during data development.
接着,在步骤S13中数据处理设备通过所述开发项目处理所述脱敏数据是指数据处理方在安全的开发项目环境中对脱敏数据进行如软件开发,数据图绘等的处理但不限于此。其中,开发项目处理脱敏数据的账号或角色由数据提供的业务方指派或创建授权,接上文举例,A公司创建生产项目以及开发项目的owner指派B研究所或本公司人员为开发项目的管理员,该管理员对开发项目中所有对象均有访问权限,同时能进行用户或角色的管理与授权,如指派B研究所的数据开发人员以开发账号,开发账号拥有表或函数的创建权限从而可对A公司所提供的脱敏数据进行开发,从而便于对开发账号的安全管理,同时使得开发账号对真实数据可用但不可见。 Then, in step S13, the data processing device processes the desensitization data through the development project, that is, the data processor performs processing such as software development, data mapping, etc. on the desensitization data in a secure development project environment, but is not limited thereto. this. Among them, the account or role of the development project to deal with the desensitization data is assigned or created by the business party providing the data. In the above example, the company A creates the production project and the owner of the development project assigns the B research institute or the company personnel to the development project. Administrator, the administrator has access to all objects in the development project, and can manage and authorize the user or role, such as assigning the data developer of the B research institute to develop the account, and the development account has the permission to create the table or function. Therefore, the desensitization data provided by Company A can be developed, thereby facilitating the secure management of the development account, and making the development account available to the real data but not visible.
本领域技术人员应能理解上述开发项目中处理脱敏数据的方式仅为举例,其他现有的或今后可能出现的开发项目中处理脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of processing desensitization data in the above development projects is only an example, and other methods for processing desensitization data in existing or future development projects may be applied to the present application, and should also be included in The scope of the present application is intended to be included herein by reference.
优选地,图2示出根据本申请一个优选实例的用于进行数据处理的方法流程图。其中,包括步骤S11、步骤S12、步骤S13、步骤S14以及步骤S15。Preferably, FIG. 2 shows a flow chart of a method for performing data processing in accordance with a preferred embodiment of the present application. It includes step S11, step S12, step S13, step S14, and step S15.
具体地,在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;在步骤S12中数据处理设备将所述脱敏数据发送至对应的开发项目;在步骤S13中数据处理设备通过所述开发项目处理所述脱敏数据;在步骤S14中数据处理设备将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目;在步骤S15中数据处理设备通过所述生产项目发布所述处理结果。Specifically, in step S11, the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding development project; The data processing device processes the desensitization data by the development item in step S13; the data processing device returns the processing result of the desensitization data in the development item to the production item in step S14; in step S15 The medium data processing device issues the processing result through the production item.
在此,步骤S11、步骤S13与图1中步骤S11、步骤S13相同或相似,不再赘述。Here, step S11 and step S13 are the same as or similar to steps S11 and S13 in FIG. 1 and will not be described again.
所述数据处理设备中在步骤S14中数据处理设备将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目是指在开发项目中对脱敏数据进行处理后的处理结果返回至数据提供业务方所管控的生产项目中。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,B研究所的开发人员基于脱敏数据在开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送回生产项目中,从而使得A公司对数据处理结果进行检视或评估,从而进一步保障了数据以及数据处理结果的安全性。The data processing device returns the processing result of the desensitization data in the development project to the production item in the data processing device in step S14, which refers to the processing result after the desensitization data is processed in the development project. Return to the production project controlled by the data provider. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception. In the above example, the developer of the B research institute sends the code to the production project through the data development platform after developing the software code of the application through the development account in the development project based on the desensitization data, so that the company A processes the data processing result. Review or evaluate to further ensure the security of data and data processing results.
接着,在步骤S15中数据处理设备通过所述生产项目发布所述处理结果是指数据提供的业务方在生产项目中接受到返回的脱敏数据处理结果后对数据处理结果通过真实数据进行代码或程序性能验证或者对外输出但不限于此。其中,发布处理结果即为利用数据处理结果对其进行验证或通过真实的生产数据对其进行生产。接上文举例,A公司在生产项目中对返回的基于脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号利用真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,从而提升了对数据处理结果的安全性。Then, in step S15, the data processing device issues the processing result through the production item, which means that the data provided by the data provider receives the returned desensitization data processing result in the production item, and then performs the code on the data processing result through the real data or Program performance verification or external output is not limited to this. Among them, the release processing result is to verify the data processing result or to produce it through real production data. In the above example, Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data to test the software program of the released data. The data processing results are released in the production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
优选地,所述数据处理设备还包括步骤S16(未示出)用于设置所述开发项目关于所述脱敏数据的权限信息。即在生产项目在将真实数据进行脱敏后,同一脱敏数据可能 不止一种数据处理用途,例如,进行软件开发,进行数据分析等,此时不同的用途对数据的使用不同,因此通过设置不同的权限信息可在开发时获得对于脱敏数据不同的使用和处理权限。接上文举例,A公司的数据在软件开发时设置的脱敏数据的权项为读、创建等,在数据分析是仅为只读。设置开发项目关于脱敏数据的权项可让数据的使用更加的安全,避免开发方权限过大导致数据安全问题。进一步地,在步骤S12中数据处理设备根据所述权限信息将所述脱敏数据发送至所述开发项目是指根据对开发项目开放的关于脱敏数据的不同权限将脱敏数据有选择性的发送至开发项目,例如,A公司将需要进行某一个月数据分析的脱敏数据仅发送当月的脱敏数据,而开发软件需要的脱敏数据则是一年或一个季度的,从而使得脱敏数据的发送更有针对性,进行更好的对数据进行安全管控。Preferably, the data processing device further comprises a step S16 (not shown) for setting the rights information of the development item regarding the desensitization data. That is, after the production project desensitizes the real data, the same desensitization data may More than one type of data processing, for example, software development, data analysis, etc. At this time, different uses have different data usage. Therefore, different usage rights information can be used to obtain different usage and processing of desensitization data during development. Permissions. In the above example, the data of the company A's desensitization data set during software development is read, created, etc., and the data analysis is only read-only. Setting the development project's rights to desensitize data can make data usage more secure and avoid data security issues caused by excessive developer permissions. Further, sending the desensitization data to the development item according to the authority information in step S12 means that the desensitization data is selective according to different rights regarding desensitization data open to the development project. Sent to the development project, for example, Company A will desensitize data for a month's data analysis to send only desensitization data for the current month, while the desensitization data required for development software is one year or quarter, thus making desensitization The transmission of data is more targeted and better manages the data.
基于授权方式使得不同业务方在非机密数据交换的过程中安全流通且同样可用不可见的情况,即在不同业务方需要进行非机密数据交换处理的情况下,数据提供的业务方在数据提供设备端对真实数据的关键特征进行隐匿脱敏并提供给另一业务方的数据开发方在数据应用设备端进行处理,最终再将处理结果进行处理的过程,具体如下。Based on the authorization method, different service parties can be safely circulated in the process of non-confidential data exchange and can also be invisible, that is, in the case that different business parties need to perform non-confidential data exchange processing, the data providing service party is in the data providing device. The process of hiding and desensitizing the key features of the real data and providing the data developer to another business party to process on the data application device side, and finally processing the processing result, is as follows.
图3示出根据本申请另一个方面的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的方法流程图。其中,所述数据提供设备端包括步骤S11、步骤S12以及步骤S13;所述数据应用设备端包括步骤S21以及步骤S22。FIG. 3 is a flowchart of a method for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application. The data providing device end includes step S11, step S12, and step S13; and the data application device end includes step S21 and step S22.
具体地,在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;在步骤S12中数据处理设备通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;在步骤S13中数据处理设备根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目;在步骤S21中数据处理设备通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;在步骤S22中数据处理设备通过所述应用开发项目处理所述脱敏数据。Specifically, in step S11, the data processing device desensitizes the production data in the production project to obtain corresponding desensitization data; in step S12, the data processing device performs the application development project in the corresponding data application device through the development project. Developing a authorization process; the data processing device transmits the desensitization data to the application development project via the development project according to the result information of the development authorization process in step S13; the data processing device passes the application development project in step S21 Obtaining desensitization data from a development item in the data providing device, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device; the data processing device is developed by the application in step S22 The project processes the desensitization data.
在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据是指提供数据的业务方即数据提供设备端在所管控的安全环境中对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会致使安全问题敏感数据特征的数据。其中,生产项目是数据提供业务方所管控的安全环境,例如接上文举例,A公司同时与C公司合作联合开发某一应用软件,A公司提供软件开发的关键数据同时负责部分软件开发,C公司负责软件开发,因此在数据开发 平台中,A公司就该应用创建一个项目空间即为数据提供设备端,其中生产项目即为A公司处理真实关键数据的安全环境,A公司项目空间的创建owner指派本公司生产账号,该生产账号拥有对生产项目中除安全设置之外的所有权限,即在A公司提供数据之前,在生产项目中对数据进行脱敏处理,从而使得数据的关键安全信息得以被隐匿从而提升数据的安全保障。In step S11, the data processing device desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the data providing device side, that is, the data providing device end is sensitive to the real data in the controlled security environment. The concealment of features results in data that retains the necessary data features available to the data consumer and conceals or eliminates data characteristics that would result in security-sensitive data. Among them, the production project is a security environment controlled by the data provider business. For example, in the above example, Company A cooperates with Company C to jointly develop an application software. Company A provides key data for software development and is responsible for part of software development. The company is responsible for software development, so in data development In the platform, Company A creates a project space for the application, which is the data supply device. The production project is the security environment for Company A to process real key data. The creation owner of Project A of the company assigns the production account of the company. It has all the rights except the security settings in the production project, that is, before the data is provided by Company A, the data is desensitized in the production project, so that the key security information of the data can be concealed to improve the security of the data.
接着,在步骤S12中数据处理设备通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理是指在数据提供设备端以及数据应用设备端均同时拥有生产项目以及对应的开发项目,因为生产数据为真实数据从安全角度不宜直接发送至不同业务方,因此在数据脱敏之后,脱敏数据后被发送至本项目的开发项目中,数据应用该设备端的开发项目在使用该脱敏数据前需要获得数据提供设备端所代表的业务方的授权。其中,授权方式包括向数据应用设备端的开发项目授权,从而可以通过数据开发平台进行发送或者通过SFTP或其它安全文件传输方式进行但不限于此,或者对数据应用设备端开发项目中的开发账号进行授权,使得开发账号可以直接读取数据提供设备端开发项目中的脱敏数据,接上文举例,C公司在需要A公司数据进行软件开发时在数据开发平台中发起对A公司所管控的开发项目中对应脱敏数据的申请,A公司在数据开发平台中通过表间进行ACL授权的方式对C公司的开发项目中的开发账号进行授权,从而使得脱敏数据可以在开发环境中安全流转。Then, in step S12, the data processing device performs development authorization processing on the application development project in the corresponding data application device through the development project, which means that both the data providing device end and the data application device end have both the production project and the corresponding development project, because The production data is real data and should not be sent directly to different business parties from the security point of view. Therefore, after the data is desensitized, the desensitization data is sent to the development project of the project, and the data application application development project of the device side uses the desensitization data. It is necessary to obtain the authorization of the business party represented by the data providing device side. The authorization method includes authorizing the development project to the data application device, so that it can be sent through the data development platform or through SFTP or other secure file transfer methods, but is not limited thereto, or the development account in the data application device development project is performed. Authorization, so that the development account can directly read the desensitization data in the data-providing device-side development project. In the above example, C company initiates the development and control of company A in the data development platform when it needs A company data for software development. In the project, corresponding to the application of desensitization data, Company A authorizes the development account in the development project of Company C through the ACL authorization between the tables in the data development platform, so that the desensitization data can be safely transferred in the development environment.
本领域技术人员应能理解上述开发项目中开发授权的方式仅为举例,其他现有的或今后可能出现的开发项目中开发授权的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of developing authorization in the above development projects is only an example, and other ways of developing authorization in existing or future development projects may be applicable to the present application, and should also be included in the scope of protection of the present application. It is hereby incorporated by reference.
接着,在步骤S13中数据处理设备根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目是指在数据应用设备端的开发项目获得授权后数据提供设备端将所管控的开发项目中的脱敏数据发送至数据应用设备端的开发项目。发送的方式包括但不限于通过数据开发平台进行发送或数据应用设备端的开发项目中开发账号直接根据授权进行读取,或者通过SFTP或其它安全文件传输方式进行但不限于此,接上文举例,C公司的开发账号被A公司通过数据提供设备端的开发项目授权后根据权限对脱敏数据进行读取,从而达到脱敏数据可见,生产数据不可见的效果,保障了真实数据在数据交换过程中的安全。Then, in step S13, the data processing device sends the desensitization data to the application development project via the development project according to the result information of the development authorization process, which means that the data is provided after the development project of the data application device is authorized. The device side sends the desensitization data in the controlled development project to the development project of the data application device. The method of sending includes, but is not limited to, sending through a data development platform or developing a project in a data application device. The development account is directly read according to the authorization, or is performed by SFTP or other secure file transmission method, but is not limited thereto. The development account of Company C is read by the company A through the development project of the data providing device, and then the desensitization data is read according to the authority, so that the desensitization data is visible, the production data is invisible, and the real data is guaranteed in the data exchange process. Security.
接着,脱敏数据获取装置321通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏 处理获得,即如上文所述数据应用设备端获得授权后根据授权获得数据提供设备开发项目所提供的脱敏数据,接上文举例,即C公司所管控创建的项目空间中的开发项目中的开发账号在获得授权后根据权限对脱敏数据进行读取。Next, the desensitization data obtaining means 321 acquires desensitization data from the development item in the data providing device by the application development project, wherein the desensitization data is desensitized by the production data of the production item in the data providing device The processing is obtained, that is, as described above, after obtaining the authorization of the data application device, the desensitization data provided by the data providing device development project is obtained according to the authorization, and the above example is the development project in the project space created by the management company C. The development account reads the desensitization data according to the authority after obtaining the authorization.
本领域技术人员应能理解上述获取数据提供设备端脱敏数据的方式仅为举例,其他现有的或今后可能出现的获取数据提供设备端脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of obtaining the desensitization data of the device by the above data is only an example, and other existing or future data acquisition methods for providing device-side desensitization data may be applied to the present application, and It is intended to be included within the scope of this application and is hereby incorporated by reference.
接着,在步骤S22中数据处理设备通过所述应用开发项目处理所述脱敏数据是指在数据应用设备端所管控的开发项目在获取数据提供设备端的脱敏数据后对所述脱敏数据进行处理。其中,应用开发项目即为数据应用设备端所管控的数据开发环境,由数据应用设备端所在的业务方对其中开发权限进行控制,从而有效监管数据的安全流通,接上文举例,即在数据开发平台中C公司所在的项目空间利用开发空间中授权的C公司的开发账号对所读取的A公司的脱敏数据进行开发,从而达到在业务方进行非机密数据交换处理时对脱敏数据可见而对真实数据不可见的效果。Then, the data processing device processes the desensitization data through the application development project in step S22, that is, the development project managed by the data application device performs the desensitization data after acquiring the desensitization data of the data providing device end. deal with. The application development project is a data development environment controlled by the data application device end, and the business party where the data application device end is located controls the development authority, thereby effectively supervising the safe circulation of data, and the above example, that is, the data The project space where C Company is located in the development platform utilizes the development account of the authorized C company in the development space to develop the desensitized data of the read company A, so as to achieve desensitization data when the business side performs non-confidential data exchange processing. Visible and invisible to real data.
优选地,所述数据应用设备端还包括步骤S25(未示出),用于对所述应用生产项目中的应用生产数据进行脱敏处理以获得对应的应用脱敏数据。即在数据应用设备端所管控的生产项目中可以对数据应用设备端的生产数据进行脱敏从而获得数据应用设备端的脱敏数据,接上文举例,A公司与C公司共同进行软件开发,C公司在获得A公司的脱敏数据进行开发的同时,结合C公司的真实生产数据进行软件开发,因此在数据开发平台中所管控的C公司的生产项目中对数据进行脱敏,从而得到C公司的脱敏数据。进一步地,在步骤S22中数据处理设备通过所述应用开发项目处理所述脱敏数据及所述应用脱敏数据,即数据应用设备端对的开发项目获得其对应的数据应用设备端生产项目中所提供的脱敏数据并对其进行处理,接上文举例,即C公司在数据开发平台中的开发项目对C公司生产项目所提供的C公司真实数据的脱敏数据进行开发处理,从而达到A、C公司在联合开发过程中,C公司可同时结合双方的脱敏数据进行处理又可以使得真实数据在流转过程中的安全得到保障。Preferably, the data application device further includes a step S25 (not shown) for desensitizing the application production data in the application production project to obtain corresponding application desensitization data. That is, in the production project controlled by the data application device, the production data of the data application device can be desensitized to obtain the desensitization data of the data application device end. For example, the company A and the C company jointly carry out software development, C company While obtaining the desensitization data of Company A for development, combined with the real production data of Company C for software development, the data is desensitized in the production project of Company C controlled by the data development platform, thereby obtaining the company C. Desensitization data. Further, in step S22, the data processing device processes the desensitization data and the application desensitization data through the application development project, that is, the development project of the data application device pair obtains the corresponding data application device end production project. The desensitization data provided and processed, and the above example, that is, the development project of the company C in the data development platform develops and processes the desensitization data of the real data of the C company provided by the C company production project, thereby achieving In the joint development process of A and C companies, C company can combine the desensitization data of both parties to process and ensure the security of real data in the process of circulation.
优选地,图4示出示出根据本申请另一个优选实例的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的方法流程图。其中,所述数据提供设备端包括步骤S11、步骤S12以及步骤S13;所述数据应用设备端包括步骤S21以及步骤S22;步骤S23;步骤S24。Preferably, FIG. 4 shows a flow chart showing a method for data processing implemented by the data providing device end and the data application device side according to another preferred example of the present application. The data providing device end includes step S11, step S12, and step S13; the data application device end includes step S21 and step S22; step S23; step S24.
具体地,在步骤S11中数据处理设备对生产项目中的生产数据进行脱敏处理以获得 对应的脱敏数据;在步骤S12中数据处理设备通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;在步骤S13中数据处理设备根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目;在步骤S21中数据处理设备通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;在步骤S22中数据处理设备通过所述应用开发项目处理所述脱敏数据;在步骤S23中数据处理设备将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;在步骤S24中数据处理设备通过所述应用生产项目发布所述处理结果。Specifically, the data processing device desensitizes the production data in the production item in step S11 to obtain Corresponding desensitization data; in step S12, the data processing device performs development authorization processing on the application development project in the corresponding data application device through the development project; in step S13, the data processing device according to the result information of the development authorization process The desensitization data is sent to the application development project via the development project; in step S21, the data processing device acquires desensitization data from the development project in the data providing device through the application development project, wherein the desensitization data passes through the The production data desensitization process of the production item in the data providing device is obtained; in step S22, the data processing device processes the desensitization data through the application development project; in step S23, the data processing device stores the desensitization data in the The processing result in the application development project is provided to the application production project; in step S24, the data processing device issues the processing result through the application production project.
在此,所述步骤S11、步骤S12、步骤S13、步骤S21以及步骤S22与图3中步骤S11、步骤S12、步骤S13、步骤S21以及步骤S22相同或相似,不再赘述。Here, the step S11, the step S12, the step S13, the step S21 and the step S22 are the same as or similar to the steps S11, S12, S13, S21 and S22 in FIG. 3 and will not be described again.
所述数据应用设备端中在步骤S23中数据处理设备将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目是指在数据应用设备端的开发项目中对数据提供设备端所提供的脱敏数据进行处理后的处理结果返回至数据应用设备端所管控的生产项目中。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,C公司的开发人员基于脱敏数据在开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送至C公司的生产项目中,从而使得C公司对联合开发的数据处理结果进行统一检视或评估,进一步保障了数据以及数据处理结果的安全性。Providing, in the data application device, the processing result of the desensitization data in the application development project to the application production project in the data application device in step S23, means providing data in a development project of the data application device side The processed result of the desensitization data provided by the device end is returned to the production project controlled by the data application device. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception. In the above example, the developer of Company C develops the software code of the application through the development account in the development project based on the desensitization data, and then sends the code to the production project of the C company through the data development platform, so that the company C is united. The data processing results developed are uniformly reviewed or evaluated to further ensure the security of data and data processing results.
接着,在步骤S24中数据处理设备通过所述应用生产项目发布所述处理结果是指数据应用设备端在生产项目中接受到返回的脱敏数据处理结果后对数据处理结果通过真实数据进行代码或程序性能验证或者对外输出但不限于此。其中,发布处理结果即为利用数据处理结果对其进行验证或通过在数据应用设备端获得数据提供设备端在生产项目中的授权后基于真实的生产数据对其进行生产。接上文举例,C公司在生产项目中对返回的基于A公司脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号利用A公司授权的真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,使得A公司与C公司在共同进行数据处理的过程中,开发项目对开发项目授权从而使得C公司的开发账号能读取A公司的脱敏数据,从而使得开发过程中有针对性的保护和开发数据权限,开发项目从而提升了对数据处理结果的安全性。 Then, in step S24, the data processing device issues the processing result through the application production item, that is, the data application device end receives the desensitized data processing result in the production project, and then performs the code on the data processing result through the real data or Program performance verification or external output is not limited to this. The release processing result is to verify the data processing result or to obtain the data providing device end device in the production project after the authorization of the data on the data application device, and then to produce the data based on the real production data. In the above example, C company publishes the returned program code based on the desensitization data of company A on the data development platform in the production project, and the production account uses the real data authorized by company A to execute the software program on the released data. Test work. The data processing result is released in the production space, so that the processing result is post-processed or verified in the security environment of the data provider, so that the company A and the C company cooperate in the process of data processing, and the development project authorizes the development project so that C The company's development account can read the company's desensitization data, so that the development process has targeted protection and development of data permissions, development projects to improve the security of data processing results.
优选地,所述数据提供设备端还包括步骤S14(未示出),用于通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理;步骤S15(未示出),用于根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目。所述数据应用设备端还包括步骤S26(未示出),用于通过应用生产项目获取所述数据提供设备中生产项目的生产数据。Preferably, the data providing device end further includes a step S14 (not shown) for performing a production authorization process on the application production item in the data application device by the production item; step S15 (not shown), And transmitting the production data to the application production item via the production item according to result information of the production authorization process. The data application device side further includes a step S26 (not shown) for acquiring production data of the production item in the data providing device by applying the production item.
具体地,在步骤S14中数据处理设备通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理是指数据提供设备端的所管控的生产项目通过授权账户读取数据等方式对数据应用设备端的生产项目进行授权。其中,授权的方式包括但不限于数据提供设备端中的生产项目管理账户通过表间访问控制等方式使得数据应用设备端生产空间的管理账户能够读取数据提供设备端中的生产数据,接上文举例,即A公司所管控的项目空间中生产项目的生产账号授权C公司所管控的项目空间中生产项目的生产账号,使其获得读取真实生产数据的权限,从而完成授权。Specifically, in step S14, the data processing device performs production authorization processing on the application production item in the data application device by using the production item, that is, the controlled production item of the data providing device end reads data through an authorized account, etc. The production project on the data application device is authorized. The authorization method includes, but is not limited to, the production project management account in the data providing device side, so that the management account of the data application device side production space can read the production data in the data providing device end by means of the access control between the tables, and the like. For example, the production account of the production project in the project space controlled by Company A authorizes the production account of the production project in the project space controlled by Company C, so that it can obtain the authority to read the real production data, thereby completing the authorization.
接着,在步骤S15中数据处理设备根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目是指根据数据提供设备端的授权信息将生产数据发送至数据应用设备端的所管控的生产项目中,接上文举例,即在数据开发平台中A公司对C公司所创建管理的生产项目授权后将A公司的授权生产数据发送至C公司的生产项目中,或者C公司的生产项目中的生产账号获得对A公司生产数据的读取权限从而对A公司生产数据进行读取。Next, the sending, by the data processing device, the production data to the application production item via the production item according to the result information of the production authorization processing in step S15 refers to sending the production data to the data according to the authorization information of the data providing device end. In the production project controlled by the application device, the above example is given, that is, after the authorization of the production project managed by the company C by the company A in the data development platform, the authorized production data of the company A is sent to the production project of the company C, Or the production account in the production project of Company C obtains the reading authority of the production data of Company A to read the production data of Company A.
接着,在步骤S26中数据处理设备通过应用生产项目获取所述数据提供设备中生产项目的生产数据,其中,所述步骤S23根据所述生产数据在所述应用生产项目中执行所述处理结果是指在数据应用设备端根据授权获得数据提供设备端的生产数据后,在所管控的生产项目获得基于数据提供设备端脱敏数据所得的处理结果后,通过数据提供设备端的生产数据对处理结果进行验证或执行,所述执行方式包括但不限于通过真实数据进行代码或程序性能验证或者对外输出,接上文举例,在数据开发平台中C公司在所管控的生产项目中通过生产账号对所发布的基于A公司脱敏数据得出的软件代码进行测试或通过A公司所提供给C公司的生产数据进行软件测试,从而使得生产数据只在A、C公司的生产项目环境中流通,脱敏数据仅在A、C公司的开发环境中流通,保障了在共同进行数据开发处理时,仅业务方对真实数据可见但开发方只对脱敏数据可见,从而提升了数据在非机密交换时的安全性。Next, in step S26, the data processing device acquires the production data of the production item in the data providing device by applying the production item, wherein the step S23 performs the processing result in the application production item according to the production data. After the data application device obtains the production data of the data providing device according to the authorization, after the obtained production item obtains the processing result based on the desensitization data of the data providing device, the processing result is verified by the production data of the data providing device. Or execution, the execution manner includes, but is not limited to, performing code or program performance verification or external output through real data. In the above example, in the data development platform, the company C is released through the production account pair in the controlled production project. The software code based on the desensitization data of Company A is tested or the software is tested by the production data provided by Company A to Company C, so that the production data is only distributed in the production project environment of A and C companies, and the desensitization data is only Circulated in the development environment of A and C companies, and guaranteed to be common When the line data development process, only the visible side of the business development side of real data but the data is visible only to desensitization, so as to enhance the security of data in the non-confidential exchange.
基于委托第三方平台的方式使得不同业务方的在机密数据交换及处理过程中得到安 全保障的情况,即在业务双方涉及有机密数据交换时数据提供的业务方将数据委托给双方共同信任的安全第三方,数据处理的业务方将开发人员授权添加进第三方进行数据处理,从而保障机密数据在安全的管控环境中可用但不可复制的效果,具体如下。Based on the way of entrusting third-party platforms, different business parties get security in the process of confidential data exchange and processing. In the case of full security, that is, when the business parties are involved in the exchange of confidential data, the data provided by the business party entrusts the data to a secure third party that the two parties trust, and the data processing business party adds the developer authorization to the third party for data processing, thereby The effect of ensuring that confidential data is available in a secure management environment but not replicable is as follows.
图5示出根据本申请另一个方面的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法流程图。其中,数据提供设备端包括步骤S11、步骤S12;数据应用设备端包括步骤S21;平台设备端包括步骤S31、步骤S32、步骤S33。FIG. 5 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application. The data providing device includes steps S11 and S12; the data application device includes step S21; and the platform device includes steps S31, S32, and S33.
具体地,在步骤S11中数据处理设备对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;在步骤S12中数据处理设备将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;在步骤S31中数据处理设备获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;在步骤S21中数据处理设备配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;在步骤S32中数据处理设备根据对应数据应用设备配置平台设备;在步骤S33中数据处理设备通过配置后的所述平台设备处理所述脱敏数据。Specifically, in step S11, the data processing device desensitizes the production data in the data providing device to obtain corresponding desensitization data; in step S12, the data processing device transmits the desensitization data to the corresponding platform device to Processing by the corresponding data application device; the data processing device acquires desensitization data from the data providing device in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; The data processing device in S21 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; in step S32, the data processing device configures the platform device according to the corresponding data application device The data processing device processes the desensitization data through the configured platform device in step S33.
在步骤S11中数据处理设备对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据是指在提供数据的业务方在数据提供设备端对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会致使安全问题敏感数据特征的数据。其中,生产数据是指包含关键敏感特征的真实数据,数据脱敏的方法包括但不限于在数据开发平台直接进行脱敏操作或者通过人工筛选进行,例如,A公司与D公司就某一类数据进行联合开发,同时A方的数据包含敏感机密内容不宜给D公司查看,但开发过程中D公司需要使用A公司的数据,因此双方将委托共同信任的第三方平台进行数据流转和处理,在将数据放入第三方平台之前,为保障A公司的数据安全,先在A公司所管理的安全环境中将真实数据即生产数据进行脱敏处理,从而提升数据在流转过程中的安全性。In step S11, the data processing device desensitizes the production data in the data providing device to obtain the corresponding desensitization data, which means that the business party providing the data hides the key sensitive features of the real data at the data providing device end to obtain Retains the necessary data characteristics available to data consumers and conceals or eliminates data that can cause security-sensitive data characteristics. Among them, production data refers to real data containing key sensitive features. Data desensitization methods include, but are not limited to, desensitization directly on the data development platform or through manual screening. For example, Company A and Company D have certain types of data. Joint development, while the data of Party A contains sensitive confidential content is not suitable for D company to view, but D company needs to use the data of Company A during the development process, so the two parties will entrust a third-party platform that is trusted by others to carry out data circulation and processing. Before the data is placed in the third-party platform, in order to protect the data security of Company A, the real data, that is, the production data, is desensitized in the security environment managed by Company A, thereby improving the security of the data in the process of circulation.
接着,在步骤S12中数据处理设备将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理是指在数据提供设备端将脱敏数据发送到数据处理设备端与数据提供设备端所代表的业务方所共同信任的第三方数据处理平台设备端中,从而使得数据应用设备端可以在第三方平台中进行数据处理。其中,对应的平台设备是指需要进行数据流转的业务双方所共同信任的第三方数据处理平台,例如一个共同创建的可控制相关数 据处理权限的数据处理空间或平台项目但并不限于此,接上文举例,在数据开发平台中A公司与D公司共同委托第三方作为交换过程中的管控和仲裁方,由第三方监理一个项目空间并进行安全设置,A公司将脱敏数据发送至该第三方所管控的项目空间以供D公司在第三方中对其进行处理。在此,发送脱敏数据的方式可以是通过数据开发平台直接后台发送或者通过加密文件安全传输的相关协议进行传输但并不限于此。Then, in step S12, the data processing device sends the desensitization data to the corresponding platform device for processing by the corresponding data application device, which means that the desensitization data is sent to the data processing device end and the data providing device at the data providing device end. The third-party data processing platform device side trusted by the service represented by the terminal enables the data application device to perform data processing in the third-party platform. The corresponding platform device refers to a third-party data processing platform that is trusted by both parties that need to perform data flow, such as a jointly created controllable correlation number. According to the data processing space or platform project of processing authority, but not limited to this, in the above data example, in the data development platform, Company A and Company D jointly entrust a third party as the control and arbitration party in the exchange process, and the third party supervises one. The project space is safely set up, and Company A sends the desensitization data to the project space controlled by the third party for Company D to process it in a third party. Here, the method of sending the desensitization data may be directly transmitted in the background through the data development platform or transmitted through a related protocol for secure transmission of the encrypted file, but is not limited thereto.
接着,在步骤S31中数据处理设备获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备端作为数据提供设备以及数据应用设备端共同信任的第三方所管控的安全环境,接受或在一定权限下对数据提供设备端的脱敏数据进行获取,从而便于数据应用设备端进行处理,接上文举例,数据平台中的第三方创建的项目空间通过项目空间打包授权的方式如A的项目空间直接授权第三方项目空间读取脱敏数据的权项,从而读取或接受A公司的脱敏数据。Next, the data processing device acquires desensitization data from the data providing device in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. Here, the platform device side is used as a data providing device and a security environment controlled by a third party trusted by the data application device end, and accepts or acquires the desensitization data of the data providing device end under a certain authority, thereby facilitating the data application device end. Processing, as in the above example, the project space created by the third party in the data platform is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A. The company's desensitization data.
接着,在步骤S21中数据处理设备配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得。即数据应用设备端在平台设备端进行例如将开发账号直接授权或是项目空间打包授权的方式使得数据应用设备端可在平台设端所管控的安全环境内对脱敏数据进行处理,接上文举例,D公司在数据开发平台中对第三方所管控的项目空间进行授权,从而使得D公司的开发人员可以在第三方项目空间中对数据进行处理。其中,配置平台设备的方式可以是对平台所管控的项目空间直接授权或对平台中的开发相关账号进行授权,使得数据应用设备端可以通过该账号进行数据处理但并不限于此。Next, the data processing device configures the platform device to process the desensitization data in step S21, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. That is, the data application device side performs the direct authorization of the development account or the project space package authorization on the platform device side, so that the data application device can process the desensitization data in the security environment controlled by the platform set end, For example, Company D authorizes the project space controlled by third parties in the data development platform, so that developers of Company D can process the data in the third-party project space. The method for configuring the platform device may be to directly authorize the project space controlled by the platform or authorize the development-related account in the platform, so that the data application device can perform data processing through the account, but is not limited thereto.
接着,在步骤S32中数据处理设备根据对应数据应用设备配置平台设备是指平台设备端根据数据应用设备端进行设置使得数据应用设备端可在平台设备管控的安全环境内对脱敏数据进行处理。其中,根据对应数据应用设备配置平台设备的方式包括但不限于授权数据应用设备端的开发账号可以在平台设备所管控的项目空间中进行数据处理或是数据应用设备端对平台设备端直接进行授权处理。配置平台设备使得数据应用设备端可在机密数据交换时在安全管控环境内对脱敏数据进行处理,从而提升机密数据的安全保障。Then, in step S32, the data processing device configures the platform device according to the corresponding data application device, and the platform device device performs the setting according to the data application device end, so that the data application device device can process the desensitization data in a security environment controlled by the platform device. The manner in which the platform device is configured according to the corresponding data application device includes, but is not limited to, the development account of the authorized data application device end can perform data processing in the project space controlled by the platform device or the data application device directly performs authorization processing on the platform device end. . The platform device is configured to enable the data application device to process the desensitized data in the security management environment during the confidential data exchange, thereby improving the security of the confidential data.
本领域技术人员应能理解上述配置平台设备的方式仅为举例,其他现有的或今后可能出现的配置平台设备的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。 A person skilled in the art should understand that the manner of configuring the platform device is only an example. Other existing or future possible configurations of the platform device may be applicable to the present application, and should also be included in the scope of protection of the present application. This is hereby incorporated by reference.
接着,在步骤S33中数据处理设备通过配置后的所述平台设备处理所述脱敏数据是指在平台设备所管控的第三方安全环境中,数据应用设备端根据配置平台设备端的权限对脱敏数据进行处理,接上文举例,A、D公司在数据开发平台中对第三方项目空间进行授权后将D公司的开发人员添加至第三方项目空间从而进行数据处理,从而达到数据应用设备端可以使用数据提供设备端的机密数据,同时无法将机密数据在安全管控的第三方环境中进行复制的目的,从而提升机密数据在使用和处理过程中的安全性。Then, in step S33, the data processing device processes the desensitization data through the configured platform device, and the data application device is desensitized according to the permission of the device device in the third-party security environment controlled by the platform device. Data processing, in the above example, A, D company authorized the third-party project space in the data development platform, the developer of the D company is added to the third-party project space for data processing, so that the data application device can The use of data to provide confidential data on the device side, while the confidential data can not be copied in a secure third-party environment, thereby improving the security of the use and processing of confidential data.
优选地,图6示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法中平台设备端方法示意图。其中,所述平台设备端包括步骤S34、步骤S31、步骤S32以及步骤S33。Preferably, FIG. 6 is a schematic diagram of a platform device-side method in a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application. The platform device end includes step S34, step S31, step S32, and step S33.
具体地,在步骤S34中数据处理设备在所述平台设备中创建项目;在步骤S31中数据处理设备通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;在步骤S32中数据处理设备根据对应数据应用设备配置所述项目;在步骤S33中数据处理设备通过配置后的所述项目处理所述脱敏数据。Specifically, the data processing device creates an item in the platform device in step S34; the data processing device acquires desensitization data from the data providing device through the item in step S31, wherein the desensitization data passes through the opposite The production data desensitization process is obtained in the data providing device; the data processing device configures the item according to the corresponding data application device in step S32; and the data processing device processes the desensitization data through the configured item in step S33 .
在步骤S34中数据处理设备在所述平台设备中创建项目是指在受数据提供设备端以及数据应用设备端共同信任的平台设备中创建安全的数据流转以及处理空间,使得机密数据可以在安全的项目空间中收到保护,接上文举例,在数据开发平台中A公司和D公司共同委托数据开发平台方或者双方均信任的第三方在数据开发平台中创建一个安全的项目空间,使得A、D公司可以在该项目空间中进行数据的处理和共享。In step S34, the data processing device creates a project in the platform device, which means that a secure data flow and a processing space are created in the platform device trusted by the data providing device and the data application device, so that the confidential data can be secure. In the project space, the protection is received. In the data development platform, Company A and Company D jointly commissioned the data development platform or a third party trusted by both parties to create a secure project space in the data development platform, so that A, Company D can process and share data in the project space.
本领域技术人员应能理解上述在平台设备中创建项目的方式仅为举例,其他现有的或今后可能出现的在平台设备中创建项目的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should understand that the manner of creating a project in the platform device is only an example. Other existing or future possible ways to create a project in the platform device are applicable to the present application, and should also be included in the present application. It is within the scope of protection and is hereby incorporated by reference.
接着,在步骤S31中数据处理设备通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备端所创建的项目空间通过数据提供设备端的项目空间对其直接授权的方式获得数据提供设备端中的脱敏数据,接上文举例,A公司在数据开发平台中对第三方项目空间进行授权从而使得脱敏数据只能子啊说第三方项目空间中访问,从而限制了机密数据的流传和处理范围,从而提升了数据的安全性。Next, the data processing device acquires desensitization data from the data providing device through the item in step S31, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. Here, the project space created by the platform device side obtains desensitization data in the data providing device side by directly authorizing the project space of the data providing device side. Referring to the above example, Company A is in the data development platform to the third party. The project space is authorized so that the desensitization data can only be accessed in the third-party project space, thereby limiting the circulation and processing range of the confidential data, thereby improving the security of the data.
接着,在步骤S32中数据处理设备根据对应数据应用设备配置所述项目是指平台设备端根据数据应用设备端的授权对项目空间进行设置,接上文举例,第三方项目空间获 得D公司的项目空间的授权,在第三项目空间中对D公司的开发人员进行添加,从而使得D公司的开发人员可在第三方项目空间中对A公司的脱敏数据进行处理。Then, in step S32, the data processing device configures the item according to the corresponding data application device, that is, the platform device side sets the project space according to the authorization of the data application device end, and the third-party project space is obtained as an example. The authorization of D company's project space is added to the developer of D company in the third project space, so that developers of Company D can process the desensitization data of Company A in the third-party project space.
接着,在步骤S33中数据处理设备通过配置后的所述项目处理所述脱敏数据是指数据应用设备端的开发人员或账号在经过配置后再平台设备端在所管控的安全的项目空间中对数据提供设备端所提供的脱敏数据进行处理。接上文举例,在数据开发平台中D公司获得授权或是将开发人员添加至第三方项目空间中后,在第三方项目空间中对A公司所提供的机密数据的脱敏数据进行处理,从而将机密数据的流转范围限制在项目空间中,进一步提升了机密数据的安全性。Then, in step S33, the data processing device processes the desensitized data through the configured item, that is, the developer or the account of the data application device is configured, and then the platform device end is in the controlled project space. The data provides desensitization data provided by the device side for processing. In the above example, after the D company obtains the authorization in the data development platform or adds the developer to the third-party project space, the desensitization data of the confidential data provided by the company A is processed in the third-party project space, thereby Limiting the flow of confidential data to the project space further enhances the security of confidential data.
优选地,图7示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的方法流程图。其中,所述数据提供设备端包括步骤S11、步骤S13以及步骤S12;所述数据应用设备端包括步骤S21;所述平台设备端包括步骤S34、步骤S35、步骤S31、步骤S32、步骤S33、步骤S36以及步骤S37。Preferably, FIG. 7 is a flowchart of a method for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application. The data providing device end includes step S11, step S13, and step S12; the data application device end includes step S21; and the platform device end includes step S34, step S35, step S31, step S32, step S33, and step S36 and step S37.
具体地,在步骤S34中数据处理设备在所述平台设备中创建项目;在步骤S11中数据处理设备对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;在步骤S13中数据处理设备对所述平台设备中的项目进行授权处理;在步骤S35中数据处理设备获取所述数据提供设备及所述数据应用设备对所述项目的授权信息;在步骤S12中数据处理设备将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;在步骤S31中数据处理设备根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;在步骤S21中数据处理设备配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;在步骤S32中数据处理设备根据对应数据应用设备配置所述项目;在步骤S33中数据处理设备通过配置后的所述项目处理所述脱敏数据;在步骤S36中数据处理设备将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;在步骤S37中数据处理设备通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。Specifically, in step S34, the data processing device creates an item in the platform device; in step S11, the data processing device desensitizes the production data in the data providing device to obtain corresponding desensitization data; in step S13 The data processing device performs authorization processing on the items in the platform device; in step S35, the data processing device acquires authorization information of the data providing device and the data application device for the item; in step S12, the data processing device The desensitization data is sent to the corresponding platform device for processing by the corresponding data application device; in step S31, the data processing device acquires desensitization data from the data providing device through the item according to the authorization information, where The desensitization data is obtained by desensitizing the production data in the data providing device; the data processing device configures the platform device to process desensitization data in step S21, wherein the desensitization data is passed through the data providing device The production data desensitization process is obtained; in step S32, the data processing device is configured according to the corresponding data Configuring the item; the data processing device processes the desensitization data through the configured item in step S33; and the data processing device provides the processing result of the desensitization data in the application development item in step S36 To the application production project; in step S37, the data processing device issues the processing result of the desensitization data in the development project through the production project.
在此,步骤S11、步骤S12、步骤S21与图5中的步骤S11、步骤S12、步骤S21相同或相似,不再赘述。步骤S34与图6中步骤S34相同或相似,不再赘述。Here, step S11, step S12, and step S21 are the same as or similar to step S11, step S12, and step S21 in FIG. 5 and will not be described again. Step S34 is the same as or similar to step S34 in FIG. 6, and will not be described again.
所述数据提供设备端中平台授权装置713对所述平台设备中的项目进行授权处理是指在数据提供设备端对所信任的平台设备所管控的项目空间进行授权。其中,授权的方 式可以通过数据提供设备端中的项目直接对平台设备项目进行打包授权,从而是的数据提供设备端所提供的机密数据可由平台设备的项目进行获取,接上文举例,在数据开发平台中A公司的项目空间对第三方项目空间进行打包授权,从而使得第三方项目空间的账号可对脱敏数据进行读取或第三方项目空间有接受脱敏数据的权限。Authorizing the item in the platform device by the platform authorization device 713 in the data providing device refers to authorizing the project space controlled by the trusted platform device at the data providing device end. Among them, the authorized party The platform device item can be packaged and authorized directly through the project in the data providing device, so that the confidential data provided by the data providing device can be obtained by the platform device project, and the above example is in the data development platform. The company's project space packages and authorizes the third-party project space, so that the account of the third-party project space can read the desensitization data or the third-party project space has the right to accept desensitization data.
接着,在步骤S35中数据处理设备获取所述数据提供设备及所述数据应用设备对所述项目的授权信息是指在平台设备端对数据提供设备端以及数据应用设备端的项目的授权进行接收从而使得机密数据的流转和处理均在共同信任的安全环境中流转,接上文举例,在数据开发平台中A公司以及D公司的项目空间对第三方项目空间进行打包授权,从而使得A公司的脱敏数据可在第三方项目空间中流转以及D公司的开发人员可在第三方空间中对A公司的脱敏数据进行开发。通过对平台设备端的项目授权使得数据在安全可控的环境中流转和处理,提高数据的安全性。Then, in step S35, the data processing device acquires the authorization information of the data providing device and the data application device for the item, and refers to receiving the authorization of the data providing device end and the data application device end of the platform device end. The flow and processing of confidential data are transferred in a secure environment of mutual trust. In the above example, in the data development platform, the project space of Company A and Company D package and authorize the third-party project space, thereby making the company A take off. Sensitive data can be streamed in third-party project spaces and developers of Company D can develop Desensitization data for Company A in a third-party space. Data is transferred and processed in a secure and controllable environment through project authorization on the platform device side to improve data security.
进一步地,在步骤S31中数据处理设备根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。即平台设备端的项目根据数据提供设备端的授权对脱敏数据进行相应的获取,其中,获取方式包括但不限于通过根据项目的授权对脱敏数据进行权限内的读取,接上文举例,在数据开发平台中A公司对第三方项目授予机密数据的脱敏数据的读取、复制等权限从而使得第三方项目获取A公司的脱敏数据。Further, in step S31, the data processing device acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data is taken off by the production data in the data providing device Sensitive treatment is obtained. That is, the project on the platform device side obtains the desensitization data according to the authorization of the data providing device end, wherein the obtaining manner includes, but is not limited to, reading the desensitized data within the authority according to the authorization of the project, In the data development platform, Company A grants the third-party project the right to read and copy the desensitized data of the confidential data, so that the third-party project acquires the desensitization data of Company A.
优选地,所述数据提供设备、数据应用设备以及平台设备中所述项目包括生产项目与开发项目其中,生产项目是指项目中处理真实数据的项目空间,由各业务方所管控;开发项目是指项目中开发人员处理脱敏数据所在的项目空间,由业务方指派的开发账号所使用。Preferably, the items in the data providing device, the data application device, and the platform device include a production project and a development project. The production project refers to a project space in the project that processes real data, and is controlled by each business party; the development project is Refers to the project space where the developer handles the desensitization data in the project, and is used by the development account assigned by the business party.
因此,在步骤S35中数据处理设备还用于获取所述数据提供设备及所述数据应用设备对所述生产项目的授权信息。即数据开发设备端以及数据应用设备端的生产项目对共同信任的平台设备端中的生产项目进行打包授权,从而使得两者的允许范围内所要处理的真实数据可以在安全的生产项目环境中进行共享,接上文举例,A公司和D公司在数据开发平台中对第三方项目中的生产项目进行授权,第三方项目获取授权后获得业务双方的共同开发软件所需的真实数据。Therefore, in step S35, the data processing device is further configured to acquire authorization information of the data providing device and the data application device for the production item. That is, the production project on the data development device side and the data application device side package and authorize the production items in the platform device side of the common trust, so that the real data to be processed within the allowable range of the two can be shared in a safe production project environment. In the above example, Company A and Company D authorize the production projects in the third-party projects in the data development platform, and obtain the real data required by the two parties to jointly develop the software after obtaining the authorization.
接着,在步骤S31中数据处理设备还用于根据所述授权信息通过所述开发项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备中的脱敏数据由数据提供设备端将脱敏数据提 供至仅数据应用设备端开发人员可使用的开发项目中,接上文举例,根据A公司对第三方数据的授权,第三方的开发项目获得A公司的脱敏数据,从而将开发人员添加至第三方开发项目中的开发人员可通过开发项目对A公司的脱敏数据进行处理和使用,从而保障了脱敏数据可以在第三方安全环境中被D公司开发人员所使用,但因为在第三方管控的环境中而无法将脱敏数据进行复制或留作他用,从而保障了机密数据的安全。Next, in step S31, the data processing device is further configured to acquire desensitization data from the data providing device through the development item according to the authorization information, wherein the desensitization data is passed through the data providing device Production data desensitization is obtained. Here, the desensitization data in the platform device is desensitized by the data providing device For development projects that can only be used by data application device developers, the above example, according to company A's authorization for third-party data, third-party development projects obtain desensitization data from company A, thereby adding developers to Developers in third-party development projects can use the development project to process and use the desensitization data of Company A, thus ensuring that desensitization data can be used by developers of Company D in a third-party security environment, but because it is in a third party. The desensitized data cannot be copied or used for other purposes in a controlled environment, thus ensuring the security of confidential data.
接着,在步骤S32中数据处理设备还用于根据对应数据应用设备配置所述开发项目。即通过平台设备端通过将数据应用设备中的开发账号添加至开发项目等配置方式使得数据应用设备端可在平台设备中对数据提供设备所提供的脱敏数据进行处理,接上文举例,在数据开发平台中A、D公司共同信任的第三方的开发项目空间根据D公司的申请将D公司的开发人员账户添加至第三方的项目空间中,进而对A公司的脱敏数据进行处理。Next, in step S32, the data processing device is further configured to configure the development item according to the corresponding data application device. That is, the data application device can process the desensitization data provided by the data providing device in the platform device by adding the development account in the data application device to the development project or the like through the platform device end. The development project space shared by A and D companies in the data development platform adds the developer account of Company D to the project space of the third party according to the application of Company D, and then processes the desensitization data of Company A.
接着,在步骤S33中数据处理设备还用于通过配置后的所述开发项目处理所述脱敏数据。即将数据应用设备端的开发账号或人员配置至开发项目后,在平台设备端的开发项目中对数据提供设备所提供的脱敏数据进行处理,接上文举例,在数据开发平台中D公司的开发人员或账号被添加至在第三方的开发项目空间中对A公司的脱敏数据进行开发处理,从而在第三方管控的环境中而无法将脱敏数据进行复制或留作他用,保障了机密数据的安全。Next, the data processing device is further configured to process the desensitization data through the configured development item in step S33. After the development account or personnel of the data application device is configured to the development project, the desensitization data provided by the data providing device is processed in the development project of the platform device side, and the developer of the D company in the data development platform is connected as an example. Or the account number is added to the development of the desensitization data of Company A in the third-party development project space, so that the desensitization data cannot be copied or reserved for use in a third-party controlled environment, and the confidential data is guaranteed. Security.
接着,在步骤S36中数据处理设备将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,D公司的开发人员基于脱敏数据在第三方开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送回生产项目中,从而使得A公司在第三方生产项目空间中对数据处理结果进行检视或评估,从而进一步保障了数据以及数据处理结果的安全性。Next, in step S36, the data processing device provides the processing result of the desensitization data in the application development project to the application production project. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception. In the above example, the developer of Company D develops the software code of the application through the development account in the third-party development project based on the desensitization data, and then sends the code back to the production project through the data development platform, so that Company A is in the third party. Data processing results are reviewed or evaluated in the production project space to further ensure the security of data and data processing results.
接着,在步骤S37中数据处理设备通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。其中,发布处理结果即为利用数据处理结果对其进行验证或通过真实的生产数据对其进行生产。接上文举例,A公司在生产项目中对返回的基于脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号在第三方项目空间中利用真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在第三方的生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,从而提升了对数 据处理结果的安全性。Next, in step S37, the data processing device issues the processing result of the desensitization data in the development project through the production item. Among them, the release processing result is to verify the data processing result or to produce it through real production data. In the above example, Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data in the third-party project space to execute the software program on the released data. Test work. The data processing results are published in the third-party production space, so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the logarithm According to the safety of the processing results.
优选地,数据应用设备端中还包括步骤S22(未示出)用于对所述平台设备中的项目进行授权处理。即数据应用设备端在使用和处理数据提供设备端数据的同时,在需配合自己的数据共同处理的情况下,可对平台进行授权使得平台获得数据应用该设备端的机密数据或其脱敏数据,接上文举例,在数据开发平台中D公司在第三方开发环境开发软件时需要结合D公司的机密数据与A公司的脱敏数据共同进行开发或研究,因此D公司所管控的项目空间对第三方平台项目进行授权从而提供D公司的机密数据的脱敏数据,从而使得业务双发在共同使用机密数据进行处理时双发数据均得到妥善的安全保护。Preferably, the data application device further includes a step S22 (not shown) for performing authorization processing on the items in the platform device. That is, the data application device uses the data to provide the data of the device end, and in the case that the data needs to be processed together with the data, the platform can be authorized to obtain the data to apply the confidential data of the device or the desensitization data thereof. In the above example, in the data development platform, D company needs to combine the confidential data of Company D with the desensitization data of Company A to develop or research the software in the third-party development environment. Therefore, the project space controlled by Company D is the first. The three-party platform project is authorized to provide desensitization data of D company's confidential data, so that the dual-issue data of the company's dual-issue data is properly protected when the shared data is processed.
进一步地,平台设备端还包括步骤S38(未示出),用于根据所述授权信息通过所述开发项目获取来自所述数据应用设备的应用方脱敏数据,其中,所述应用方脱敏数据通过对所述数据应用设备中的应用方生产数据脱敏处理获得。更进一步地,在步骤S33中数据处理设备还用于通过配置后的所述开发项目处理所述脱敏数据及所述应用方脱敏数据。即平台设备端根据数据应用设备的授权获得其脱敏数据,其中,包括但不限于平台设备的开发项目账号获得数据应用设备端的开发项目的访问权限或数据应用该设备端将脱敏数据发送至平台设备端,接上文举例,即D公司的开发项目中对第三方的开发项目进行授权,使得D公司的机密数据的脱敏数据可在第三方开发项目中由开发人员进行单独或配合A公司的脱敏数据进行共同处理,从而使得第三方中双方的机密数据得到共享,同时第三方的安全管控环境使得数据的输出需要征得双方的共同允许,从而保护了数据的安全。Further, the platform device end further includes a step S38 (not shown) for acquiring application desensitization data from the data application device through the development item according to the authorization information, wherein the application is desensitized The data is obtained by desensitizing the application production data in the data application device. Further, in step S33, the data processing device is further configured to process the desensitization data and the application side desensitization data by the configured development item. That is, the platform device side obtains the desensitization data according to the authorization of the data application device, wherein the development project account including but not limited to the platform device obtains the access permission of the development project of the data application device side or the data application device sends the desensitization data to the device end On the platform device side, the above example, that is, the development project of D company authorizes the development project of the third party, so that the desensitization data of the confidential data of D company can be separately or cooperated by the developer in the third-party development project. The company's desensitization data is processed together, so that the confidential data of both parties in the third party is shared, and the third-party security management environment makes the data output need to be mutually permitted by both parties, thus protecting the data security.
基于数据使用中权限的控制使得业务方所提供的数据在处理过程中可用不可见的情况,即在一个业务方需要进行数据处理的情况下,业务方对真实数据的关键特征进行隐匿脱敏并提供给数据开发方进行处理,最终再将处理结果进行处理的过程,具体如下。The control based on the permission of the data in use makes the data provided by the business party invisible in the process of processing, that is, in the case that a business party needs to perform data processing, the business party secretly desensitizes the key features of the real data and The process of providing the data developer with processing and finally processing the processing result is as follows.
图8示出根据本申请另一个方面的用于进行数据处理的设备示意图。其中,所述数据处理设备包括数据脱敏装置111、脱敏数据发送装置112以及脱敏数据处理装置113。FIG. 8 shows a schematic diagram of an apparatus for performing data processing in accordance with another aspect of the present application. The data processing device includes a data desensitizing device 111, a desensitizing data transmitting device 112, and a desensitizing data processing device 113.
具体地,所述数据处理设备中数据脱敏装置111对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;脱敏数据发送装置112将所述脱敏数据发送至对应的开发项目;脱敏数据处理装置113通过所述开发项目处理所述脱敏数据。Specifically, the data desensitizing device 111 in the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; the desensitization data transmitting device 112 sends the desensitization data to the corresponding development. The desensitization data processing device 113 processes the desensitization data by the development project.
所述数据处理设备中数据脱敏装置111对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据是指业务在所管控的安全环境中对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会致使安全问题敏 感数据特征的数据。其中,生产数据即为业务方需要处理的真实数据,生产项目即为业务方所管控的安全环境,可由业务方进行创建并掌相关控制权限如访问数据对象权限、用户管理和授权权限、资源创建等,例如,业务方A公司需要研究所B对某种应用的数据进行软件开发,可在某双方均可使用的数据开发平台中创建生产项目,该创建的账号即为生产项目的owner可访问生产项目中的所有资源并对用户或账号进行授权以及设置生产项目的安全设置,owner可指派一个生产账号使得其拥有除安全设置之外的全部权限,从而生产账号可以对A公司开发某应用软件的真实数据进行脱敏处理。在业务方管控的安全环境中对真实数据进行脱敏,使得数据的关键安全信息得以被隐匿从而提升数据的安全保障。The data desensitizing device 111 in the data processing device desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the business hides the key sensitive features of the real data in the controlled security environment to obtain Retaining the necessary data features available to data users and hiding or eliminating them can cause security problems Data that senses the characteristics of the data. The production data is the real data that the business party needs to process. The production project is the security environment controlled by the business party. It can be created by the business party and has relevant control rights such as accessing data object permissions, user management and authorization rights, and resource creation. For example, business company A needs research institute B to develop software for data of an application, and can create a production project in a data development platform that can be used by both parties. The created account is accessible to the owner of the production project. Produce all the resources in the project and authorize the user or account and set the security settings of the production project. The owner can assign a production account to have all the permissions except the security settings, so that the production account can develop an application for company A. The real data is desensitized. Desensitize real data in a secure environment controlled by the business side, so that key security information of the data can be concealed to improve data security.
本领域技术人员应能理解上述获取脱敏数据的方式仅为举例,其他现有的或今后可能出现的获取脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should understand that the above manner of obtaining desensitization data is only an example, and other existing or future possible methods for obtaining desensitization data may be applicable to the present application, and should also be included in the scope of protection of the present application. It is hereby incorporated by reference.
接着,脱敏数据发送装置112将所述脱敏数据发送至对应的开发项目是指通过安全的方式例如通过共同信任的数据开发平台将脱敏数据发送至使用和处理数据方所管控的安全环境中。其中,所述开发项目即为数据提供方所信任的由数据处理方进行数据处理的安全环境,接上文举例,A公司在需要对某应用的数据进行软件开发处理时,在数据开发平台中创建生产项目的同时创建相应的开发项目并将开发项目中的开发相关权限如创建表、函数、资源等权限赋予B研究所的开发账号,从而可经由数据开发平台直接将脱敏数据从生产项目发送至开发项目中。发送脱敏数据的方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收,但并不限于此。将脱敏数据发送至数据提供业务方所信任的安全开发项目环境中,可提升数据开发过程中的安全可控性。Then, the desensitization data transmitting device 112 sends the desensitization data to the corresponding development project, which means sending the desensitized data to a security environment controlled by the data processing and controlling the data in a secure manner, for example, through a data platform of mutual trust. in. The development project is a security environment that is trusted by the data provider for data processing by the data processing party. In the above example, the company A needs to perform software development processing on the data of an application in the data development platform. Create a production project and create a corresponding development project and assign development-related permissions such as creating tables, functions, resources, etc. in the development project to the development account of the B Institute, so that the desensitization data can be directly from the production project via the data development platform. Send to the development project. The manner of sending the desensitization data includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices, but is not limited thereto. Send desensitized data to the security development project environment trusted by the data provider to improve security and controllability during data development.
接着,脱敏数据处理装置113通过所述开发项目处理所述脱敏数据是指数据处理方在安全的开发项目环境中对脱敏数据进行如软件开发,数据图绘等的处理但不限于此。其中,开发项目处理脱敏数据的账号或角色由数据提供的业务方指派或创建授权,接上文举例,A公司创建生产项目以及开发项目的owner指派B研究所或本公司人员为开发项目的管理员,该管理员对开发项目中所有对象均有访问权限,同时能进行用户或角色的管理与授权,如指派B研究所的数据开发人员以开发账号,开发账号拥有表或函数的创建权限从而可对A公司所提供的脱敏数据进行开发,从而便于对开发账号的安全管理,同时使得开发账号对真实数据可用但不可见。 Then, the desensitization data processing device 113 processes the desensitization data through the development project, which means that the data processor performs processing such as software development, data mapping, etc. on the desensitization data in a secure development project environment, but is not limited thereto. . Among them, the account or role of the development project to deal with the desensitization data is assigned or created by the business party providing the data. In the above example, the company A creates the production project and the owner of the development project assigns the B research institute or the company personnel to the development project. Administrator, the administrator has access to all objects in the development project, and can manage and authorize the user or role, such as assigning the data developer of the B research institute to develop the account, and the development account has the permission to create the table or function. Therefore, the desensitization data provided by Company A can be developed, thereby facilitating the secure management of the development account, and making the development account available to the real data but not visible.
本领域技术人员应能理解上述开发项目中处理脱敏数据的方式仅为举例,其他现有的或今后可能出现的开发项目中处理脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of processing desensitization data in the above development projects is only an example, and other methods for processing desensitization data in existing or future development projects may be applied to the present application, and should also be included in The scope of the present application is intended to be included herein by reference.
优选地,图9示出根据本申请另一个优选实例的用于进行数据处理的设备示意图。其中,所述数据处理设备包括数据脱敏装置211、脱敏数据发送装置212、脱敏数据处理装置213、数据处理结果提供装置214以及数据处理结果发布装置215。Preferably, FIG. 9 shows a schematic diagram of an apparatus for performing data processing in accordance with another preferred embodiment of the present application. The data processing device includes a data desensitizing device 211, a desensitizing data transmitting device 212, a desensitizing data processing device 213, a data processing result providing device 214, and a data processing result issuing device 215.
具体地,所述数据处理设备中数据脱敏装置211对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;脱敏数据发送装置212将所述脱敏数据发送至对应的开发项目;脱敏数据处理装置213通过所述开发项目处理所述脱敏数据;数据处理结果提供装置214将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目;数据处理结果发布装置215通过所述生产项目发布所述处理结果。Specifically, the data desensitizing device 211 in the data processing device desensitizes the production data in the production item to obtain corresponding desensitization data; the desensitization data transmitting device 212 sends the desensitization data to the corresponding development. The desensitization data processing device 213 processes the desensitization data by the development project; the data processing result providing device 214 returns the processing result of the desensitization data in the development project to the production project; data processing The result issuing device 215 issues the processing result through the production item.
在此,数据脱敏装置211、脱敏数据处理装置213与图8中数据脱敏装置111、脱敏数据处理装置113相同或相似,不再赘述。Here, the data desensitizing device 211 and the desensitizing data processing device 213 are the same as or similar to the data desensitizing device 111 and the desensitizing data processing device 113 in FIG. 8 and will not be described again.
所述数据处理设备中数据处理结果提供装置214将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目是指在开发项目中对脱敏数据进行处理后的处理结果返回至数据提供业务方所管控的生产项目中。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,B研究所的开发人员基于脱敏数据在开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送回生产项目中,从而使得A公司对数据处理结果进行检视或评估,从而进一步保障了数据以及数据处理结果的安全性。The data processing result providing means 214 in the data processing device returns the processing result of the desensitization data in the development item to the production item, which means that the processing result after the desensitization data is processed in the development item is returned. To the production project controlled by the data provider. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception. In the above example, the developer of the B research institute sends the code to the production project through the data development platform after developing the software code of the application through the development account in the development project based on the desensitization data, so that the company A processes the data processing result. Review or evaluate to further ensure the security of data and data processing results.
接着,数据处理结果发布装置215通过所述生产项目发布所述处理结果是指数据提供的业务方在生产项目中接受到返回的脱敏数据处理结果后对数据处理结果通过真实数据进行代码或程序性能验证或者对外输出但不限于此。其中,发布处理结果即为利用数据处理结果对其进行验证或通过真实的生产数据对其进行生产。接上文举例,A公司在生产项目中对返回的基于脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号利用真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,从而提升了对数据处理结果的安全性。 Then, the data processing result issuing device 215 issues the processing result through the production item, which means that the data provided by the data provider receives the returned desensitization data processing result in the production item, and then performs the code or the program on the data processing result through the real data. Performance verification or external output is not limited to this. Among them, the release processing result is to verify the data processing result or to produce it through real production data. In the above example, Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data to test the software program of the released data. The data processing results are released in the production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
优选地,所述数据处理设备还包括脱敏数据权限设置装置216(未示出)用于设置所述开发项目关于所述脱敏数据的权限信息。即在生产项目在将真实数据进行脱敏后,同一脱敏数据可能不止一种数据处理用途,例如,进行软件开发,进行数据分析等,此时不同的用途对数据的使用不同,因此通过设置不同的权限信息可在开发时获得对于脱敏数据不同的使用和处理权限。接上文举例,A公司的数据在软件开发时设置的脱敏数据的权项为读、创建等,在数据分析是仅为只读。设置开发项目关于脱敏数据的权项可让数据的使用更加的安全,避免开发方权限过大导致数据安全问题。进一步地,所述脱敏数据发送装置212根据所述权限信息将所述脱敏数据发送至所述开发项目是指根据对开发项目开放的关于脱敏数据的不同权限将脱敏数据有选择性的发送至开发项目,例如,A公司将需要进行某一个月数据分析的脱敏数据仅发送当月的脱敏数据,而开发软件需要的脱敏数据则是一年或一个季度的,从而使得脱敏数据的发送更有针对性,进行更好的对数据进行安全管控。Preferably, the data processing device further includes desensitization data authority setting means 216 (not shown) for setting authority information of the development item regarding the desensitization data. That is, after the production project desensitizes the real data, the same desensitization data may be used for more than one type of data processing, for example, software development, data analysis, etc., at this time, different uses of the data are different, so by setting Different permission information can be used differently for the desensitization data during development. In the above example, the data of the company A's desensitization data set during software development is read, created, etc., and the data analysis is only read-only. Setting the development project's rights to desensitize data can make data usage more secure and avoid data security issues caused by excessive developer permissions. Further, the desensitizing data transmitting device 212 sending the desensitization data to the development project according to the authority information refers to selectively desensitizing data according to different rights regarding desensitization data open to a development project. Sending to the development project, for example, Company A will need to perform desensitization data for a month of data analysis to send only desensitization data for the current month, while the desensitization data required for development software is one year or one quarter, thus making it take off The transmission of sensitive data is more targeted and better manages the data.
基于授权方式使得不同业务方在非机密数据交换的过程中安全流通且同样可用不可见的情况,即在不同业务方需要进行非机密数据交换处理的情况下,数据提供的业务方在数据提供设备端对真实数据的关键特征进行隐匿脱敏并提供给另一业务方的数据开发方在数据应用设备端进行处理,最终再将处理结果进行处理的过程,具体如下。Based on the authorization method, different service parties can be safely circulated in the process of non-confidential data exchange and can also be invisible, that is, in the case that different business parties need to perform non-confidential data exchange processing, the data providing service party is in the data providing device. The process of hiding and desensitizing the key features of the real data and providing the data developer to another business party to process on the data application device side, and finally processing the processing result, is as follows.
图10示出根据本申请另一个方面的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的设备示意图。其中,所述数据提供设备端包括数据脱敏装置311、开发授权装置312以及脱敏数据发送装置313;所述数据应用设备端包括脱敏数据获取装置321以及脱敏数据处理装置322。FIG. 10 is a schematic diagram of an apparatus for performing data processing implemented by a data providing device end and a data application device end according to another aspect of the present application. The data providing device includes a data desensitizing device 311, a development authorization device 312, and a desensitization data transmitting device 313. The data application device includes a desensitizing data acquiring device 321 and a desensitizing data processing device 322.
具体地,数据脱敏装置311对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;开发授权装置312通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;脱敏数据发送装置313根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目;脱敏数据获取装置321通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;脱敏数据处理装置322通过所述应用开发项目处理所述脱敏数据。Specifically, the data desensitizing device 311 desensitizes the production data in the production project to obtain corresponding desensitization data; the development authorization device 312 develops and authorizes the application development project in the corresponding data application device through the development project; The sensitive data transmitting device 313 sends the desensitized data to the application development project via the development project according to the result information of the development authorization process; the desensitization data obtaining device 321 acquires the development from the data providing device through the application development project Desensitization data of the item, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device; the desensitization data processing device 322 processes the desensitization data by the application development project.
所述数据脱敏装置311对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据是指提供数据的业务方即数据提供设备端在所管控的安全环境中对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会 致使安全问题敏感数据特征的数据。其中,生产项目是数据提供业务方所管控的安全环境,例如接上文举例,A公司同时与C公司合作联合开发某一应用软件,A公司提供软件开发的关键数据同时负责部分软件开发,C公司负责软件开发,因此在数据开发平台中,A公司就该应用创建一个项目空间即为数据提供设备端,其中生产项目即为A公司处理真实关键数据的安全环境,A公司项目空间的创建owner指派本公司生产账号,该生产账号拥有对生产项目中除安全设置之外的所有权限,即在A公司提供数据之前,在生产项目中对数据进行脱敏处理,从而使得数据的关键安全信息得以被隐匿从而提升数据的安全保障。The data desensitizing device 311 desensitizes the production data in the production project to obtain the corresponding desensitization data, which means that the data providing device side, that is, the data providing device end is sensitive to the real data in the controlled security environment. The concealment of features to obtain the necessary data features that are reserved for use by data consumers and to conceal or eliminate Data that results in security-sensitive data characteristics. Among them, the production project is a security environment controlled by the data provider business. For example, in the above example, Company A cooperates with Company C to jointly develop an application software. Company A provides key data for software development and is responsible for part of software development. The company is responsible for software development. Therefore, in the data development platform, Company A creates a project space for the application, which is the data supply device. The production project is the security environment for Company A to process real critical data, and the creation of owner A project space. Assigning the company's production account, the production account has all the rights except the security settings in the production project, that is, the data is desensitized in the production project before the company A provides the data, so that the key security information of the data can be Be concealed to improve data security.
接着,开发授权装置312通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理是指在数据提供设备端以及数据应用设备端均同时拥有生产项目以及对应的开发项目,因为生产数据为真实数据从安全角度不宜直接发送至不同业务方,因此在数据脱敏之后,脱敏数据后被发送至本项目的开发项目中,数据应用该设备端的开发项目在使用该脱敏数据前需要获得数据提供设备端所代表的业务方的授权。其中,授权方式包括向数据应用设备端的开发项目授权,从而可以通过数据开发平台进行发送或者通过SFTP或其它安全文件传输方式进行但不限于此,或者对数据应用设备端开发项目中的开发账号进行授权,使得开发账号可以直接读取数据提供设备端开发项目中的脱敏数据,接上文举例,C公司在需要A公司数据进行软件开发时在数据开发平台中发起对A公司所管控的开发项目中对应脱敏数据的申请,A公司在数据开发平台中通过表间进行ACL授权的方式对C公司的开发项目中的开发账号进行授权,从而使得脱敏数据可以在开发环境中安全流转。Then, the development authorization device 312 develops the authorization processing for the application development project in the corresponding data application device through the development project, which means that both the data providing device end and the data application device end have both the production project and the corresponding development project, because the production data is The real data should not be sent directly to different business parties from the security point of view. Therefore, after the data is desensitized, the desensitization data is sent to the development project of the project, and the development project of the data application device needs to obtain the desensitization data before using the desensitization data. The data provides authorization for the business party represented by the device side. The authorization method includes authorizing the development project to the data application device, so that it can be sent through the data development platform or through SFTP or other secure file transfer methods, but is not limited thereto, or the development account in the data application device development project is performed. Authorization, so that the development account can directly read the desensitization data in the data-providing device-side development project. In the above example, C company initiates the development and control of company A in the data development platform when it needs A company data for software development. In the project, corresponding to the application of desensitization data, Company A authorizes the development account in the development project of Company C through the ACL authorization between the tables in the data development platform, so that the desensitization data can be safely transferred in the development environment.
本领域技术人员应能理解上述开发项目中开发授权的方式仅为举例,其他现有的或今后可能出现的开发项目中开发授权的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of developing authorization in the above development projects is only an example, and other ways of developing authorization in existing or future development projects may be applicable to the present application, and should also be included in the scope of protection of the present application. It is hereby incorporated by reference.
接着,脱敏数据发送装置313根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目是指在数据应用设备端的开发项目获得授权后数据提供设备端将所管控的开发项目中的脱敏数据发送至数据应用设备端的开发项目。发送的方式包括但不限于通过数据开发平台进行发送或数据应用设备端的开发项目中开发账号直接根据授权进行读取,或者通过SFTP或其它安全文件传输方式进行但不限于此,接上文举例,C公司的开发账号被A公司通过数据提供设备端的开发项目授权后根据权限对脱敏数据进行读取,从而达到脱敏数据可见,生产数据不可见的效果,保障了 真实数据在数据交换过程中的安全。Then, the desensitization data transmitting device 313 sends the desensitization data to the application development project via the development project according to the result information of the development authorization process, and refers to the data providing device after the development project of the data application device end is authorized. The terminal sends the desensitization data in the controlled development project to the development project on the data application device side. The method of sending includes, but is not limited to, sending through a data development platform or developing a project in a data application device. The development account is directly read according to the authorization, or is performed by SFTP or other secure file transmission method, but is not limited thereto. The development account of Company C is read by the company A through the development project of the data providing device, and the desensitization data is read according to the authority, so that the desensitization data is visible and the production data is invisible, and the protection is guaranteed. The security of real data during the data exchange process.
接着,脱敏数据获取装置321通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得,即如上文所述数据应用设备端获得授权后根据授权获得数据提供设备开发项目所提供的脱敏数据,接上文举例,即C公司所管控创建的项目空间中的开发项目中的开发账号在获得授权后根据权限对脱敏数据进行读取。Next, the desensitization data obtaining means 321 acquires desensitization data from the development item in the data providing device through the application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device, That is, as described above, after the data application device is authorized, the desensitization data provided by the data providing device development project is obtained according to the authorization, and the above example, that is, the development account in the development project in the project space created by the C company is controlled. After obtaining authorization, the desensitization data is read according to the authority.
本领域技术人员应能理解上述获取数据提供设备端脱敏数据的方式仅为举例,其他现有的或今后可能出现的获取数据提供设备端脱敏数据的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。Those skilled in the art should be able to understand that the manner of obtaining the desensitization data of the device by the above data is only an example, and other existing or future data acquisition methods for providing device-side desensitization data may be applied to the present application, and It is intended to be included within the scope of this application and is hereby incorporated by reference.
接着,脱敏数据处理装置322通过所述应用开发项目处理所述脱敏数据是指在数据应用设备端所管控的开发项目在获取数据提供设备端的脱敏数据后对所述脱敏数据进行处理。其中,应用开发项目即为数据应用设备端所管控的数据开发环境,由数据应用设备端所在的业务方对其中开发权限进行控制,从而有效监管数据的安全流通,接上文举例,即在数据开发平台中C公司所在的项目空间利用开发空间中授权的C公司的开发账号对所读取的A公司的脱敏数据进行开发,从而达到在业务方进行非机密数据交换处理时对脱敏数据可见而对真实数据不可见的效果。Then, the desensitization data processing device 322 processes the desensitization data by using the application development project, where the development project managed by the data application device processes the desensitization data after acquiring the desensitization data of the data providing device end. . The application development project is a data development environment controlled by the data application device end, and the business party where the data application device end is located controls the development authority, thereby effectively supervising the safe circulation of data, and the above example, that is, the data The project space where C Company is located in the development platform utilizes the development account of the authorized C company in the development space to develop the desensitized data of the read company A, so as to achieve desensitization data when the business side performs non-confidential data exchange processing. Visible and invisible to real data.
优选地,所述数据应用设备端还包括数据脱敏装置325(未示出),用于对所述应用生产项目中的应用生产数据进行脱敏处理以获得对应的应用脱敏数据。即在数据应用设备端所管控的生产项目中可以对数据应用设备端的生产数据进行脱敏从而获得数据应用设备端的脱敏数据,接上文举例,A公司与C公司共同进行软件开发,C公司在获得A公司的脱敏数据进行开发的同时,结合C公司的真实生产数据进行软件开发,因此在数据开发平台中所管控的C公司的生产项目中对数据进行脱敏,从而得到C公司的脱敏数据。进一步地,所述脱敏数据处理装置322还用于通过所述应用开发项目处理所述脱敏数据及所述应用脱敏数据,即数据应用设备端对的开发项目获得其对应的数据应用设备端生产项目中所提供的脱敏数据并对其进行处理,接上文举例,即C公司在数据开发平台中的开发项目对C公司生产项目所提供的C公司真实数据的脱敏数据进行开发处理,从而达到A、C公司在联合开发过程中,C公司可同时结合双方的脱敏数据进行处理又可以使得真实数据在流转过程中的安全得到保障。Preferably, the data application device side further includes a data desensitizing device 325 (not shown) for desensitizing the application production data in the application production project to obtain corresponding application desensitization data. That is, in the production project controlled by the data application device, the production data of the data application device can be desensitized to obtain the desensitization data of the data application device end. For example, the company A and the C company jointly carry out software development, C company While obtaining the desensitization data of Company A for development, combined with the real production data of Company C for software development, the data is desensitized in the production project of Company C controlled by the data development platform, thereby obtaining the company C. Desensitization data. Further, the desensitization data processing device 322 is further configured to process the desensitization data and the application desensitization data by using the application development project, that is, the data application device-side development project obtains its corresponding data application device. The desensitization data provided in the end production project is processed and processed. The above example, that is, the development project of C company in the data development platform develops the desensitization data of the real data of the C company provided by the C company production project. Processing, so that A and C companies in the joint development process, C company can combine the desensitization data of both parties for processing and can ensure the security of real data in the process of circulation.
优选地,图11示出示出根据本申请另一个优选实例的数据提供设备端以及数据应用设备端配合实现的一种用于进行数据处理的设备示意图期中,其中,所述数据提供设备 端包括数据脱敏装置411、开发授权装置412以及脱敏数据发送装置413;所述数据应用设备端包括脱敏数据获取装置421以及脱敏数据处理装置422;数据处理结果提供装置423;数据处理结果发布装置424。Preferably, FIG. 11 shows a schematic diagram of a device for performing data processing, which is implemented by a data providing device end and a data application device end according to another preferred embodiment of the present application, wherein the data providing device The end includes a data desensitizing device 411, a development authorization device 412, and a desensitization data transmitting device 413; the data application device end includes desensitization data acquiring device 421 and desensitization data processing device 422; data processing result providing device 423; data processing The result is published 424.
具体地,数据脱敏装置411对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;开发授权装置412通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;脱敏数据发送装置413根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目;脱敏数据获取装置421通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;脱敏数据处理装置422通过所述应用开发项目处理所述脱敏数据;数据处理结果提供装置423将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;数据处理结果发布装置424通过所述应用生产项目发布所述处理结果。Specifically, the data desensitizing device 411 desensitizes the production data in the production project to obtain corresponding desensitization data; and the development authorization device 412 develops and authorizes the application development project in the corresponding data application device through the development project; The sensitive data transmitting device 413 sends the desensitized data to the application development project via the development project according to the result information of the development authorization process; the desensitization data acquiring device 421 acquires the development from the data providing device through the application development project Desensitization data of the item, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device; the desensitization data processing device 422 processes the desensitization data by the application development project; The data processing result providing means 423 supplies the processing result of the desensitization data in the application development item to the application production item; the data processing result issuing means 424 issues the processing result through the application production item.
在此,所述数据脱敏装置411、开发授权装置412、脱敏数据发送装置413、脱敏数据获取装置421以及脱敏数据处理装置422与图10中数据脱敏装置311、开发授权装置312、脱敏数据发送装置313、脱敏数据获取装置321以及脱敏数据处理装置322相同或相似,不再赘述。Here, the data desensitizing device 411, the development authorizing device 412, the desensitizing data transmitting device 413, the desensitizing data acquiring device 421, and the desensitizing data processing device 422 are the same as the data desensitizing device 311 and the development authorizing device 312 in FIG. The desensitization data transmitting device 313, the desensitizing data acquiring device 321, and the desensitizing data processing device 322 are the same or similar and will not be described again.
所述数据应用设备端中数据处理结果提供装置423将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目是指在数据应用设备端的开发项目中对数据提供设备端所提供的脱敏数据进行处理后的处理结果返回至数据应用设备端所管控的生产项目中。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,C公司的开发人员基于脱敏数据在开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送至C公司的生产项目中,从而使得C公司对联合开发的数据处理结果进行统一检视或评估,进一步保障了数据以及数据处理结果的安全性。The data processing result providing means 423 in the data application device side provides the processing result of the desensitization data in the application development project to the application production item, and refers to the data providing device in the development project of the data application device side The processed result of the desensitization data provided by the terminal is returned to the production project controlled by the data application device. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes, but is not limited to, a background system of the data development platform or a secure channel such as SFTP is established between the computer devices for transmission and reception. In the above example, the developer of Company C develops the software code of the application through the development account in the development project based on the desensitization data, and then sends the code to the production project of the C company through the data development platform, so that the company C is united. The data processing results developed are uniformly reviewed or evaluated to further ensure the security of data and data processing results.
接着,数据处理结果发布装置424通过所述应用生产项目发布所述处理结果是指数据应用设备端在生产项目中接受到返回的脱敏数据处理结果后对数据处理结果通过真实数据进行代码或程序性能验证或者对外输出但不限于此。其中,发布处理结果即为利用数据处理结果对其进行验证或通过在数据应用设备端获得数据提供设备端在生产项目中的授权后基于真实的生产数据对其进行生产。接上文举例,C公司在生产项目中对返回 的基于A公司脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号利用A公司授权的真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,使得A公司与C公司在共同进行数据处理的过程中,开发项目对开发项目授权从而使得C公司的开发账号能读取A公司的脱敏数据,从而使得开发过程中有针对性的保护和开发数据权限,开发项目从而提升了对数据处理结果的安全性。Then, the data processing result issuing device 424 issues the processing result through the application production item, which means that the data application device receives the returned desensitization data processing result in the production project, and then performs the code or the program on the data processing result through the real data. Performance verification or external output is not limited to this. The release processing result is to verify the data processing result or to obtain the data providing device end device in the production project after the authorization of the data on the data application device, and then to produce the data based on the real production data. In the above example, Company C returns to the production project. The program code based on the desensitization data development of company A is released on the data development platform, and the production account uses the real data authorized by company A to test the software program of the released data. The data processing result is released in the production space, so that the processing result is post-processed or verified in the security environment of the data provider, so that the company A and the C company cooperate in the process of data processing, and the development project authorizes the development project so that C The company's development account can read the company's desensitization data, so that the development process has targeted protection and development of data permissions, development projects to improve the security of data processing results.
优选地,所述数据提供设备端还包括生产授权装置414(未示出),用于通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理;生产数据发送装置415(未示出),用于根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目。所述数据应用设备端还包括生产数据获取装置426(未示出),用于通过应用生产项目获取所述数据提供设备中生产项目的生产数据。Preferably, the data providing device end further includes a production authorization device 414 (not shown) for performing production authorization processing on the application production item in the data application device by the production item; and the production data transmitting device 415 ( Not shown) for transmitting the production data to the application production item via the production item according to result information of the production authorization process. The data application device side further includes a production data acquisition device 426 (not shown) for acquiring production data of the production items in the data providing device by applying the production item.
具体地,所述生产授权装置414(未示出)通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理是指数据提供设备端的所管控的生产项目通过授权账户读取数据等方式对数据应用设备端的生产项目进行授权。其中,授权的方式包括但不限于数据提供设备端中的生产项目管理账户通过表间访问控制等方式使得数据应用设备端生产空间的管理账户能够读取数据提供设备端中的生产数据,接上文举例,即A公司所管控的项目空间中生产项目的生产账号授权C公司所管控的项目空间中生产项目的生产账号,使其获得读取真实生产数据的权限,从而完成授权。Specifically, the production authorization device 414 (not shown) performs production authorization processing on the application production item in the data application device by the production item, that is, the controlled production item of the data providing device end is read by the authorized account. Data, etc., authorize production projects on the data application device side. The authorization method includes, but is not limited to, the production project management account in the data providing device side, so that the management account of the data application device side production space can read the production data in the data providing device end by means of the access control between the tables, and the like. For example, the production account of the production project in the project space controlled by Company A authorizes the production account of the production project in the project space controlled by Company C, so that it can obtain the authority to read the real production data, thereby completing the authorization.
接着,生产数据发送装置415(未示出),用于根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目是指根据数据提供设备端的授权信息将生产数据发送至数据应用设备端的所管控的生产项目中,接上文举例,即在数据开发平台中A公司对C公司所创建管理的生产项目授权后将A公司的授权生产数据发送至C公司的生产项目中,或者C公司的生产项目中的生产账号获得对A公司生产数据的读取权限从而对A公司生产数据进行读取。Next, a production data transmitting device 415 (not shown) for transmitting the production data to the application production item via the production item according to the result information of the production authorization process means authorizing information according to the data providing device side The production data is sent to the controlled production project of the data application device side. For example, in the data development platform, after the company A authorizes the production project managed by the C company, the authorized production data of the company A is sent to the C. In the production project of the company, or the production account in the production project of C company, the reading authority of the production data of company A is obtained to read the production data of company A.
接着,生产数据获取装置426(未示出),用于通过应用生产项目获取所述数据提供设备中生产项目的生产数据,其中,所述数据处理结果发布装置423根据所述生产数据在所述应用生产项目中执行所述处理结果是指在数据应用设备端根据授权获得数据提供设备端的生产数据后,在所管控的生产项目获得基于数据提供设备端脱敏数据所得的处理结果后,通过数据提供设备端的生产数据对处理结果进行验证或执行,所述执行方 式包括但不限于通过真实数据进行代码或程序性能验证或者对外输出,接上文举例,在数据开发平台中C公司在所管控的生产项目中通过生产账号对所发布的基于A公司脱敏数据得出的软件代码进行测试或通过A公司所提供给C公司的生产数据进行软件测试,从而使得生产数据只在A、C公司的生产项目环境中流通,脱敏数据仅在A、C公司的开发环境中流通,保障了在共同进行数据开发处理时,仅业务方对真实数据可见但开发方只对脱敏数据可见,从而提升了数据在非机密交换时的安全性。Next, a production data obtaining means 426 (not shown) for acquiring production data of the production item in the data providing device by applying the production item, wherein the data processing result issuing means 423 is based on the production data The execution result of the processing in the application production project refers to that after the data application device obtains the production data of the data providing device according to the authorization, after obtaining the processing result obtained based on the desensitization data of the data providing device on the controlled production item, the data is passed. Providing production data of the device side to verify or execute the processing result, the executing party The formula includes, but is not limited to, code or program performance verification or external output through real data. In the above example, in the data development platform, the company C releases the desensitization data based on the company A through the production account in the controlled production project. The obtained software code is tested or tested by the production data provided by Company A to Company C, so that the production data is only distributed in the production project environment of A and C companies. The desensitization data is only in A and C companies. The circulation in the development environment ensures that when the data development process is jointly performed, only the business party can see the real data, but the developer only sees the desensitization data, thereby improving the security of the data during non-confidential exchange.
基于委托第三方平台的方式使得不同业务方的在机密数据交换及处理过程中得到安全保障的情况,即在业务双方涉及有机密数据交换时数据提供的业务方将数据委托给双方共同信任的安全第三方,数据处理的业务方将开发人员授权添加进第三方进行数据处理,从而保障机密数据在安全的管控环境中可用但不可复制的效果,具体如下。Based on the way of entrusting a third-party platform, the different business parties are secured in the process of confidential data exchange and processing, that is, the business side providing data to the two parties in the business involved in the confidential data exchange entrusts the data to the mutual trust security. Third-party, the data processing business side adds the developer authorization to the third party for data processing, thus ensuring the effect that the confidential data is available but not replicable in a secure management environment, as follows.
图12示出根据本申请另一个方面的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备示意图。其中,数据提供设备端包括数据脱敏装置511、脱敏数据发送装置512;数据应用设备端包括平台配置装置521;平台设备端包括脱敏数据获取装置531、配置装置532、脱敏数据处理装置533。FIG. 12 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another aspect of the present application. The data providing device includes a data desensitizing device 511 and a desensitizing data transmitting device 512. The data application device includes a platform configuration device 521. The platform device includes a desensitizing data acquiring device 531, a configuration device 532, and a desensitizing data processing device. 533.
具体地,数据提供设备端中数据脱敏装置511对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;脱敏数据发送装置512将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;平台设备端中脱敏数据获取装置531获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;数据应用设备端中平台配置装置521配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;平台设备端中配置装置532根据对应数据应用设备配置平台设备;脱敏数据处理装置533通过配置后的所述平台设备处理所述脱敏数据。Specifically, the data desensitizing device 511 in the data providing device performs desensitization processing on the production data in the data providing device to obtain corresponding desensitization data; the desensitizing data transmitting device 512 transmits the desensitized data to the corresponding platform. The device is processed by the corresponding data application device; the desensitization data obtaining device 531 in the platform device end acquires desensitization data from the data providing device, wherein the desensitization data is desensitized by the production data in the data providing device The data acquisition device platform configuration device 521 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; the platform device end configuration device 532 is configured according to The platform device is configured to correspond to the data application device; the desensitization data processing device 533 processes the desensitization data through the configured platform device.
所述数据提供设备端中数据脱敏装置511对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据是指在提供数据的业务方在数据提供设备端对真实数据进行关键敏感特征的隐匿从而获得既保留可供数据使用方使用的必要数据特征又隐匿或消除了会致使安全问题敏感数据特征的数据。其中,生产数据是指包含关键敏感特征的真实数据,数据脱敏的方法包括但不限于在数据开发平台直接进行脱敏操作或者通过人工筛选进行,例如,A公司与D公司就某一类数据进行联合开发,同时A方的数据包含敏感机密内容不宜给D公司查看,但开发过程中D公司需要使用A公司的数据,因此双方将委托共同信任的第三方平台进行数据流转和处理,在将数据放入第三方平台之前,为保 障A公司的数据安全,先在A公司所管理的安全环境中将真实数据即生产数据进行脱敏处理,从而提升数据在流转过程中的安全性。The data desensitizing device 511 in the data providing device desensitizes the production data in the data providing device to obtain the corresponding desensitized data, which means that the data providing device is sensitive to the real data at the data providing device end. The concealment of features results in data that retains the necessary data features available to the data consumer and conceals or eliminates data characteristics that would result in security-sensitive data. Among them, production data refers to real data containing key sensitive features. Data desensitization methods include, but are not limited to, desensitization directly on the data development platform or through manual screening. For example, Company A and Company D have certain types of data. Joint development, while the data of Party A contains sensitive confidential content is not suitable for D company to view, but D company needs to use the data of Company A during the development process, so the two parties will entrust a third-party platform that is trusted by others to carry out data circulation and processing. Before the data is placed on a third-party platform, Data security of the company A, first desensitize the real data, that is, the production data in the security environment managed by Company A, thereby improving the security of the data in the process of circulation.
接着,脱敏数据发送装置512将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理是指在数据提供设备端将脱敏数据发送到数据处理设备端与数据提供设备端所代表的业务方所共同信任的第三方数据处理平台设备端中,从而使得数据应用设备端可以在第三方平台中进行数据处理。其中,对应的平台设备是指需要进行数据流转的业务双方所共同信任的第三方数据处理平台,例如一个共同创建的可控制相关数据处理权限的数据处理空间或平台项目但并不限于此,接上文举例,在数据开发平台中A公司与D公司共同委托第三方作为交换过程中的管控和仲裁方,由第三方监理一个项目空间并进行安全设置,A公司将脱敏数据发送至该第三方所管控的项目空间以供D公司在第三方中对其进行处理。在此,发送脱敏数据的方式可以是通过数据开发平台直接后台发送或者通过加密文件安全传输的相关协议进行传输但并不限于此。Then, the desensitizing data sending device 512 sends the desensitized data to the corresponding platform device for processing by the corresponding data application device, and means sending the desensitized data to the data processing device end and the data providing device end at the data providing device end. The third-party data processing platform device side trusted by the represented business parties enables the data application device side to perform data processing in the third-party platform. The corresponding platform device refers to a third-party data processing platform that is trusted by both parties of the data flow, such as a data processing space or platform project that can jointly create related data processing permissions, but is not limited thereto. In the above example, in the data development platform, Company A and Company D jointly entrust a third party as the control and arbitration party in the exchange process. The third party supervises a project space and performs security settings. Company A sends desensitization data to the first The project space controlled by the three parties is for the company D to process it in a third party. Here, the method of sending the desensitization data may be directly transmitted in the background through the data development platform or transmitted through a related protocol for secure transmission of the encrypted file, but is not limited thereto.
接着,平台设备端中脱敏数据获取装置531获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备端作为数据提供设备以及数据应用设备端共同信任的第三方所管控的安全环境,接受或在一定权限下对数据提供设备端的脱敏数据进行获取,从而便于数据应用设备端进行处理,接上文举例,数据平台中的第三方创建的项目空间通过项目空间打包授权的方式如A的项目空间直接授权第三方项目空间读取脱敏数据的权项,从而读取或接受A公司的脱敏数据。Next, the desensitization data acquisition means 531 in the platform device side acquires desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. Here, the platform device side is used as a data providing device and a security environment controlled by a third party trusted by the data application device end, and accepts or acquires the desensitization data of the data providing device end under a certain authority, thereby facilitating the data application device end. Processing, as in the above example, the project space created by the third party in the data platform is authorized by the project space, such as the project space of A, to directly authorize the third-party project space to read the desensitization data, thereby reading or accepting A. The company's desensitization data.
接着,数据应用设备端中平台配置装置521配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得。即数据应用设备端在平台设备端进行例如将开发账号直接授权或是项目空间打包授权的方式使得数据应用设备端可在平台设端所管控的安全环境内对脱敏数据进行处理,接上文举例,D公司在数据开发平台中对第三方所管控的项目空间进行授权,从而使得D公司的开发人员可以在第三方项目空间中对数据进行处理。其中,配置平台设备的方式可以是对平台所管控的项目空间直接授权或对平台中的开发相关账号进行授权,使得数据应用设备端可以通过该账号进行数据处理但并不限于此。Next, the platform configuration device 521 in the data application device configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. That is, the data application device side performs the direct authorization of the development account or the project space package authorization on the platform device side, so that the data application device can process the desensitization data in the security environment controlled by the platform set end, For example, Company D authorizes the project space controlled by third parties in the data development platform, so that developers of Company D can process the data in the third-party project space. The method for configuring the platform device may be to directly authorize the project space controlled by the platform or authorize the development-related account in the platform, so that the data application device can perform data processing through the account, but is not limited thereto.
接着,平台设备端中配置装置532根据对应数据应用设备配置平台设备是指平台设备端根据数据应用设备端进行设置使得数据应用设备端可在平台设备管控的安全环境内对脱敏数据进行处理。其中,根据对应数据应用设备配置平台设备的方式包括但不限于 授权数据应用设备端的开发账号可以在平台设备所管控的项目空间中进行数据处理或是数据应用设备端对平台设备端直接进行授权处理。配置平台设备使得数据应用设备端可在机密数据交换时在安全管控环境内对脱敏数据进行处理,从而提升机密数据的安全保障。Then, the platform device configuration device 532 configures the platform device according to the corresponding data application device. The platform device device is configured according to the data application device end, so that the data application device terminal can process the desensitization data in a security environment controlled by the platform device. The manner in which the platform device is configured according to the corresponding data application device includes but is not limited to The development account of the authorization data application device can perform data processing in the project space controlled by the platform device or the data application device directly performs authorization processing on the platform device end. The platform device is configured to enable the data application device to process the desensitized data in the security management environment during the confidential data exchange, thereby improving the security of the confidential data.
本领域技术人员应能理解上述配置平台设备的方式仅为举例,其他现有的或今后可能出现的配置平台设备的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。A person skilled in the art should understand that the manner of configuring the platform device is only an example. Other existing or future possible configurations of the platform device may be applicable to the present application, and should also be included in the scope of protection of the present application. This is hereby incorporated by reference.
接着,脱敏数据处理装置533通过配置后的所述平台设备处理所述脱敏数据是指在平台设备所管控的第三方安全环境中,数据应用设备端根据配置平台设备端的权限对脱敏数据进行处理,接上文举例,A、D公司在数据开发平台中对第三方项目空间进行授权后将D公司的开发人员添加至第三方项目空间从而进行数据处理,从而达到数据应用设备端可以使用数据提供设备端的机密数据,同时无法将机密数据在安全管控的第三方环境中进行复制的目的,从而提升机密数据在使用和处理过程中的安全性。Then, the desensitization data processing device 533 processes the desensitization data by using the configured platform device, and the data application device end desensitizes the data according to the authority of the device platform in the third-party security environment controlled by the platform device. For processing, in the above example, A and D companies authorized the third-party project space in the data development platform, and then added the developer of the D company to the third-party project space for data processing, so that the data application device can be used. Data provides confidential data on the device side, and at the same time, confidential data cannot be copied in a secure third-party environment, thereby improving the security of confidential data during use and processing.
优选地,图13示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备中平台设备端示意图。其中,所述平台设备端包括平台项目创建装置634、脱敏数据获取装置631、配置装置632以及脱敏数据处理装置633。Preferably, FIG. 13 is a schematic diagram of a platform device end in a device for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application. The platform device end includes a platform item creation device 634, a desensitization data acquisition device 631, a configuration device 632, and a desensitization data processing device 633.
具体地,所述平台设备端中平台项目创建装置634在所述平台设备中创建项目;脱敏数据获取装置631通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;配置装置632根据对应数据应用设备配置所述项目;脱敏数据处理装置633通过配置后的所述项目处理所述脱敏数据。Specifically, the platform item creation device 634 in the platform device side creates an item in the platform device; the desensitization data obtaining device 631 acquires desensitization data from the data providing device through the item, wherein the desensitization data Obtained by the desensitization process of the production data in the data providing device; the configuration device 632 configures the item according to the corresponding data application device; the desensitization data processing device 633 processes the desensitization data through the configured item.
所述平台设备端中平台项目创建装置634在所述平台设备中创建项目是指在受数据提供设备端以及数据应用设备端共同信任的平台设备中创建安全的数据流转以及处理空间,使得机密数据可以在安全的项目空间中收到保护,接上文举例,在数据开发平台中A公司和D公司共同委托数据开发平台方或者双方均信任的第三方在数据开发平台中创建一个安全的项目空间,使得A、D公司可以在该项目空间中进行数据的处理和共享。The platform item creation device 634 in the platform device side creates a project in the platform device, which means creating a secure data flow and processing space in the platform device trusted by the data providing device end and the data application device end, so that the confidential data is made. You can receive protection in a secure project space. For example, in the data development platform, Company A and Company D jointly commission a data development platform or a third party trusted by both parties to create a secure project space in the data development platform. So that A and D companies can process and share data in the project space.
本领域技术人员应能理解上述在平台设备中创建项目的方式仅为举例,其他现有的或今后可能出现的在平台设备中创建项目的方式如可适用于本申请,也应包含在本申请保护范围以内,并在此以引用方式包含于此。 Those skilled in the art should understand that the manner of creating a project in the platform device is only an example. Other existing or future possible ways to create a project in the platform device are applicable to the present application, and should also be included in the present application. It is within the scope of protection and is hereby incorporated by reference.
接着,脱敏数据获取装置631通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备端所创建的项目空间通过数据提供设备端的项目空间对其直接授权的方式获得数据提供设备端中的脱敏数据,接上文举例,A公司在数据开发平台中对第三方项目空间进行授权从而使得脱敏数据只能子啊说第三方项目空间中访问,从而限制了机密数据的流传和处理范围,从而提升了数据的安全性。Next, the desensitization data acquiring means 631 acquires desensitization data from the data providing device by the item, wherein the desensitization data is obtained by desensitizing the production data in the data providing device. Here, the project space created by the platform device side obtains desensitization data in the data providing device side by directly authorizing the project space of the data providing device side. Referring to the above example, Company A is in the data development platform to the third party. The project space is authorized so that the desensitization data can only be accessed in the third-party project space, thereby limiting the circulation and processing range of the confidential data, thereby improving the security of the data.
接着,配置装置632根据对应数据应用设备配置所述项目是指平台设备端根据数据应用设备端的授权对项目空间进行设置,接上文举例,第三方项目空间获得D公司的项目空间的授权,在第三项目空间中对D公司的开发人员进行添加,从而使得D公司的开发人员可在第三方项目空间中对A公司的脱敏数据进行处理。Then, the configuration device 632 configures the item according to the corresponding data application device, that is, the platform device side sets the project space according to the authorization of the data application device end. Referring to the above example, the third-party project space obtains the authorization of the project space of the D company. In the third project space, the developers of Company D are added, so that the developers of Company D can process the desensitization data of Company A in the third-party project space.
接着,脱敏数据处理装置633通过配置后的所述项目处理所述脱敏数据是指数据应用设备端的开发人员或账号在经过配置后再平台设备端在所管控的安全的项目空间中对数据提供设备端所提供的脱敏数据进行处理。接上文举例,在数据开发平台中D公司获得授权或是将开发人员添加至第三方项目空间中后,在第三方项目空间中对A公司所提供的机密数据的脱敏数据进行处理,从而将机密数据的流转范围限制在项目空间中,进一步提升了机密数据的安全性。Then, the desensitization data processing device 633 processes the desensitization data through the configured item, that is, the developer or the account of the data application device side is configured, and then the platform device end pairs the data in the controlled project space. The desensitization data provided by the device is provided for processing. In the above example, after the D company obtains the authorization in the data development platform or adds the developer to the third-party project space, the desensitization data of the confidential data provided by the company A is processed in the third-party project space, thereby Limiting the flow of confidential data to the project space further enhances the security of confidential data.
优选地,图14示出根据本申请另一个优选实例的数据提供设备端、数据应用设备端以及平台设备端配合实现的一种用于实现数据处理的设备示意图。其中,所述数据提供设备端包括数据脱敏装置711、平台授权装置713以及脱敏数据发送装置712;所述数据应用设备端包括配置装置721;所述平台设备端包括平台项目创建装置734、授权获取装置735、脱敏数据获取装置731、配置装置732、脱敏数据处理装置733、数据处理结果提供装置736以及数据处理结果发布装置737。Preferably, FIG. 14 is a schematic diagram of an apparatus for implementing data processing implemented by a data providing device end, a data application device end, and a platform device end according to another preferred embodiment of the present application. The data providing device end includes a data desensitizing device 711, a platform authorization device 713, and a desensitization data transmitting device 712; the data application device end includes a configuration device 721; the platform device end includes a platform item creating device 734, The authorization acquisition means 735, the desensitization data acquisition means 731, the configuration means 732, the desensitization data processing means 733, the data processing result providing means 736, and the data processing result issuing means 737.
具体地,平台项目创建装置734在所述平台设备中创建项目;数据脱敏装置711对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;平台授权装置713对所述平台设备中的项目进行授权处理;授权获取装置735获取所述数据提供设备及所述数据应用设备对所述项目的授权信息;脱敏数据发送装置712将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理;脱敏数据获取装置731根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;平台配置装置721配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得;配置装置 732根据对应数据应用设备配置所述项目;脱敏数据处理装置733通过配置后的所述项目处理所述脱敏数据;数据处理结果提供装置736将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;数据处理结果发布装置737通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。Specifically, the platform item creation means 734 creates an item in the platform device; the data desensitization means 711 desensitizes the production data in the data providing device to obtain corresponding desensitization data; the platform authorization means 713 pairs the platform The item in the device performs authorization processing; the authorization obtaining device 735 acquires authorization information of the data providing device and the data application device for the item; the desensitization data transmitting device 712 sends the desensitization data to the corresponding platform device For the corresponding data application device to process; the desensitization data obtaining device 731 acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data passes through the data providing device The production data desensitization process is obtained; the platform configuration device 721 configures the platform device to process the desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device; 732 configuring the item according to the corresponding data application device; the desensitization data processing device 733 processes the desensitization data through the configured item; and the data processing result providing device 736 stores the desensitization data in the application development project The processing result is provided to the application production item; the data processing result issuing means 737 issues the processing result of the desensitization data in the development item through the production item.
在此,数据脱敏装置711、脱敏数据发送装置712、平台配置装置721与图12中的数据脱敏装置511、脱敏数据发送装置512、平台配置装置521相同或相似,不再赘述。平台项目创建装置734与图13中平台项目创建装置634相同或相似,不再赘述。Here, the data desensitizing device 711, the desensitizing data transmitting device 712, and the platform arranging device 721 are the same as or similar to the data desensitizing device 511, the desensitizing data transmitting device 512, and the platform arranging device 521 in FIG. The platform project creation device 734 is the same as or similar to the platform project creation device 634 in FIG. 13 and will not be described again.
所述数据提供设备端中平台授权装置713对所述平台设备中的项目进行授权处理是指在数据提供设备端对所信任的平台设备所管控的项目空间进行授权。其中,授权的方式可以通过数据提供设备端中的项目直接对平台设备项目进行打包授权,从而是的数据提供设备端所提供的机密数据可由平台设备的项目进行获取,接上文举例,在数据开发平台中A公司的项目空间对第三方项目空间进行打包授权,从而使得第三方项目空间的账号可对脱敏数据进行读取或第三方项目空间有接受脱敏数据的权限。Authorizing the item in the platform device by the platform authorization device 713 in the data providing device refers to authorizing the project space controlled by the trusted platform device at the data providing device end. The authorization method can directly package and authorize the platform device item through the item in the data providing device, so that the confidential data provided by the data providing device end can be obtained by the platform device item, and the above example is in the data. The project space of Company A in the development platform packages and authorizes the third-party project space, so that the account of the third-party project space can read the desensitization data or the third-party project space has the right to accept desensitization data.
接着,平台设备端中授权获取装置735获取所述数据提供设备及所述数据应用设备对所述项目的授权信息是指在平台设备端对数据提供设备端以及数据应用设备端的项目的授权进行接收从而使得机密数据的流转和处理均在共同信任的安全环境中流转,接上文举例,在数据开发平台中A公司以及D公司的项目空间对第三方项目空间进行打包授权,从而使得A公司的脱敏数据可在第三方项目空间中流转以及D公司的开发人员可在第三方空间中对A公司的脱敏数据进行开发。通过对平台设备端的项目授权使得数据在安全可控的环境中流转和处理,提高数据的安全性。Then, the authorization obtaining device 735 in the platform device end obtains the authorization information of the data providing device and the data application device for the item, and refers to the authorization of the data providing device end and the data application device end of the platform device end. Therefore, the flow and processing of confidential data are transferred in a secure environment of mutual trust. In the above example, in the data development platform, the project space of company A and company D packages and authorizes the third-party project space, thereby making company A Desensitization data can be streamed in third-party project spaces and developers of Company D can develop desensitization data for Company A in a third-party space. Data is transferred and processed in a secure and controllable environment through project authorization on the platform device side to improve data security.
进一步地,平台设备端中脱敏数据获取装置731根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。即平台设备端的项目根据数据提供设备端的授权对脱敏数据进行相应的获取,其中,获取方式包括但不限于通过根据项目的授权对脱敏数据进行权限内的读取,接上文举例,在数据开发平台中A公司对第三方项目授予机密数据的脱敏数据的读取、复制等权限从而使得第三方项目获取A公司的脱敏数据。Further, the desensitization data obtaining means 731 in the platform device end acquires desensitization data from the data providing device through the item according to the authorization information, wherein the desensitization data is passed through the data providing device Production data desensitization is obtained. That is, the project on the platform device side obtains the desensitization data according to the authorization of the data providing device end, wherein the obtaining manner includes, but is not limited to, reading the desensitized data within the authority according to the authorization of the project, In the data development platform, Company A grants the third-party project the right to read and copy the desensitized data of the confidential data, so that the third-party project acquires the desensitization data of Company A.
优选地,所述数据提供设备、数据应用设备以及平台设备中所述项目包括生产项目与开发项目其中,生产项目是指项目中处理真实数据的项目空间,由各业务方所管控;开发项目是指项目中开发人员处理脱敏数据所在的项目空间,由业务方指派的开发账号所使用。 Preferably, the items in the data providing device, the data application device, and the platform device include a production project and a development project. The production project refers to a project space in the project that processes real data, and is controlled by each business party; the development project is Refers to the project space where the developer handles the desensitization data in the project, and is used by the development account assigned by the business party.
因此,所述平台设备端中授权获取装置735还用于获取所述数据提供设备及所述数据应用设备对所述生产项目的授权信息。即数据开发设备端以及数据应用设备端的生产项目对共同信任的平台设备端中的生产项目进行打包授权,从而使得两者的允许范围内所要处理的真实数据可以在安全的生产项目环境中进行共享,接上文举例,A公司和D公司在数据开发平台中对第三方项目中的生产项目进行授权,第三方项目获取授权后获得业务双方的共同开发软件所需的真实数据。Therefore, the authorization obtaining device 735 of the platform device end is further configured to acquire authorization information of the data providing device and the data application device for the production item. That is, the production project on the data development device side and the data application device side package and authorize the production items in the platform device side of the common trust, so that the real data to be processed within the allowable range of the two can be shared in a safe production project environment. In the above example, Company A and Company D authorize the production projects in the third-party projects in the data development platform, and obtain the real data required by the two parties to jointly develop the software after obtaining the authorization.
接着,所述平台设备端中脱敏数据获取装置731还用于根据所述授权信息通过所述开发项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。在此,平台设备中的脱敏数据由数据提供设备端将脱敏数据提供至仅数据应用设备端开发人员可使用的开发项目中,接上文举例,根据A公司对第三方数据的授权,第三方的开发项目获得A公司的脱敏数据,从而将开发人员添加至第三方开发项目中的开发人员可通过开发项目对A公司的脱敏数据进行处理和使用,从而保障了脱敏数据可以在第三方安全环境中被D公司开发人员所使用,但因为在第三方管控的环境中而无法将脱敏数据进行复制或留作他用,从而保障了机密数据的安全。Then, the desensitization data obtaining device 731 in the platform device end is further configured to acquire desensitization data from the data providing device by using the development item according to the authorization information, wherein the desensitization data passes the The production data desensitization process in the data providing device is obtained. Here, the desensitization data in the platform device is provided by the data providing device side to the desalination data to the development project that can be used only by the data application device developer, and according to the above example, according to the authorization of the company A for the third party data, The third-party development project obtains the desensitization data of Company A, so that the developer who adds the developer to the third-party development project can process and use the desensitization data of Company A through the development project, thereby ensuring that the desensitization data can be It is used by developers of Company D in a third-party security environment, but because the desensitized data cannot be copied or reserved for use in a third-party controlled environment, the security of confidential data is guaranteed.
接着,所述平台设备端中配置装置732还用于根据对应数据应用设备配置所述开发项目。即通过平台设备端通过将数据应用设备中的开发账号添加至开发项目等配置方式使得数据应用设备端可在平台设备中对数据提供设备所提供的脱敏数据进行处理,接上文举例,在数据开发平台中A、D公司共同信任的第三方的开发项目空间根据D公司的申请将D公司的开发人员账户添加至第三方的项目空间中,进而对A公司的脱敏数据进行处理。Then, the platform device end configuration device 732 is further configured to configure the development project according to the corresponding data application device. That is, the data application device can process the desensitization data provided by the data providing device in the platform device by adding the development account in the data application device to the development project or the like through the platform device end. The development project space shared by A and D companies in the data development platform adds the developer account of Company D to the project space of the third party according to the application of Company D, and then processes the desensitization data of Company A.
接着,所述平台设备端中脱敏数据处理装置733还用于通过配置后的所述开发项目处理所述脱敏数据。即将数据应用设备端的开发账号或人员配置至开发项目后,在平台设备端的开发项目中对数据提供设备所提供的脱敏数据进行处理,接上文举例,在数据开发平台中D公司的开发人员或账号被添加至在第三方的开发项目空间中对A公司的脱敏数据进行开发处理,从而在第三方管控的环境中而无法将脱敏数据进行复制或留作他用,保障了机密数据的安全。Then, the desensitization data processing device 733 in the platform device end is further configured to process the desensitization data through the configured development item. After the development account or personnel of the data application device is configured to the development project, the desensitization data provided by the data providing device is processed in the development project of the platform device side, and the developer of the D company in the data development platform is connected as an example. Or the account number is added to the development of the desensitization data of Company A in the third-party development project space, so that the desensitization data cannot be copied or reserved for use in a third-party controlled environment, and the confidential data is guaranteed. Security.
接着,平台设备端中数据处理结果提供装置736将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目。其中,脱敏数据处理结果包括但不限于基于脱敏数据所开发的软件代码,绘制的数据走势图等。脱敏数据处理结果的返回方式包括 但不限于数据开发平台的后台系统或者通过计算机设备间建立安全通道例如SFTP等进行发送与接收。接上文举例,D公司的开发人员基于脱敏数据在第三方开发项目中通过开发账号将应用的软件代码开发完毕后将代码通过数据开发平台发送回生产项目中,从而使得A公司在第三方生产项目空间中对数据处理结果进行检视或评估,从而进一步保障了数据以及数据处理结果的安全性。Next, the data processing result providing means 736 in the platform device side provides the processing result of the desensitization data in the application development project to the application production item. Among them, desensitization data processing results include, but are not limited to, software code developed based on desensitization data, plotted data charts, and the like. The return method of desensitization data processing results includes However, it is not limited to the background system of the data development platform or the establishment of a secure channel such as SFTP between the computer devices for transmission and reception. In the above example, the developer of Company D develops the software code of the application through the development account in the third-party development project based on the desensitization data, and then sends the code back to the production project through the data development platform, so that Company A is in the third party. Data processing results are reviewed or evaluated in the production project space to further ensure the security of data and data processing results.
接着,平台设端中数据处理结果发布装置737通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。其中,发布处理结果即为利用数据处理结果对其进行验证或通过真实的生产数据对其进行生产。接上文举例,A公司在生产项目中对返回的基于脱敏数据开发的程序代码在数据开发平台上进行发布,其生产账号在第三方项目空间中利用真实数据对发布后的数据进行软件程序的测试工作。将数据处理结果在第三方的生产空间进行发布使得处理结果在数据提供方的安全环境内进行后期处理或验证,从而提升了对数据处理结果的安全性。Next, the data processing result issuing means 737 in the platform set end issues the processing result of the desensitizing data in the development item through the production item. Among them, the release processing result is to verify the data processing result or to produce it through real production data. In the above example, Company A publishes the returned program code based on desensitization data on the data development platform in the production project, and the production account uses the real data in the third-party project space to execute the software program on the released data. Test work. The data processing results are released in the third-party production space so that the processing results are post-processed or verified within the data provider's secure environment, thereby improving the security of the data processing results.
优选地,数据应用设备端中还包括平台授权装置722(未示出)用于对所述平台设备中的项目进行授权处理。即数据应用设备端在使用和处理数据提供设备端数据的同时,在需配合自己的数据共同处理的情况下,可对平台进行授权使得平台获得数据应用该设备端的机密数据或其脱敏数据,接上文举例,在数据开发平台中D公司在第三方开发环境开发软件时需要结合D公司的机密数据与A公司的脱敏数据共同进行开发或研究,因此D公司所管控的项目空间对第三方平台项目进行授权从而提供D公司的机密数据的脱敏数据,从而使得业务双发在共同使用机密数据进行处理时双发数据均得到妥善的安全保护。Preferably, the data application device side further includes a platform authorization device 722 (not shown) for performing authorization processing on the items in the platform device. That is, the data application device uses the data to provide the data of the device end, and in the case that the data needs to be processed together with the data, the platform can be authorized to obtain the data to apply the confidential data of the device or the desensitization data thereof. In the above example, in the data development platform, D company needs to combine the confidential data of Company D with the desensitization data of Company A to develop or research the software in the third-party development environment. Therefore, the project space controlled by Company D is the first. The three-party platform project is authorized to provide desensitization data of D company's confidential data, so that the dual-issue data of the company's dual-issue data is properly protected when the shared data is processed.
进一步地,平台设备端还包括应用方脱敏数据获取装置738(未示出),用于根据所述授权信息通过所述开发项目获取来自所述数据应用设备的应用方脱敏数据,其中,所述应用方脱敏数据通过对所述数据应用设备中的应用方生产数据脱敏处理获得。更进一步地,所述脱敏数据处理装置733还用于通过配置后的所述开发项目处理所述脱敏数据及所述应用方脱敏数据。即平台设备端根据数据应用设备的授权获得其脱敏数据,其中,包括但不限于平台设备的开发项目账号获得数据应用设备端的开发项目的访问权限或数据应用该设备端将脱敏数据发送至平台设备端,接上文举例,即D公司的开发项目中对第三方的开发项目进行授权,使得D公司的机密数据的脱敏数据可在第三方开发项目中由开发人员进行单独或配合A公司的脱敏数据进行共同处理,从而使得第三方中双方的机密数据得到共享,同时第三方的安全管控环境使得数据的输出需要征得双方的共 同允许,从而保护了数据的安全。Further, the platform device side further includes an application-side desensitization data acquisition device 738 (not shown) for acquiring application-side desensitization data from the data application device through the development project according to the authorization information, where The application desensitization data is obtained by desensitizing the application side production data in the data application device. Further, the desensitization data processing device 733 is further configured to process the desensitization data and the application side desensitization data through the configured development item. That is, the platform device side obtains the desensitization data according to the authorization of the data application device, wherein the development project account including but not limited to the platform device obtains the access permission of the development project of the data application device side or the data application device sends the desensitization data to the device end On the platform device side, the above example, that is, the development project of D company authorizes the development project of the third party, so that the desensitization data of the confidential data of D company can be separately or cooperated by the developer in the third-party development project. The company's desensitization data is processed together, so that the confidential data of both parties in the third party is shared, and the third-party security management environment makes the data output need to be shared by both parties. Same as allowed, thus protecting the security of the data.
对于本领域技术人员而言,显然本申请不限于上述示范性实施例的细节,而且在不背离本申请的精神或基本特征的情况下,能够以其他的具体形式实现本申请。因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本申请的范围由所附权利要求而不是上述说明限定,因此旨在将落在权利要求的等同要件的含义和范围内的所有变化涵括在本申请内。不应将权利要求中的任何附图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或步骤,单数不排除复数。装置权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第一,第二等词语用来表示名称,不表示任何特定顺序。 It is obvious to those skilled in the art that the present application is not limited to the details of the above-described exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present application. Therefore, the present embodiments are to be considered as illustrative and not restrictive, and the scope of the invention is defined by the appended claims instead All changes in the meaning and scope of equivalent elements are included in this application. Any reference signs in the claims should not be construed as limiting the claim. In addition, it is to be understood that the word "comprising" does not exclude other elements or steps. A plurality of units or devices recited in the device claims may also be implemented by a unit or device by software or hardware. The first, second, etc. words are used to indicate names and do not represent any particular order.

Claims (38)

  1. 一种用于进行数据处理的方法,其中,该方法包括:A method for data processing, wherein the method comprises:
    对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;Desensitizing the production data in the production project to obtain corresponding desensitization data;
    将所述脱敏数据发送至对应的开发项目;Sending the desensitization data to a corresponding development project;
    通过所述开发项目处理所述脱敏数据。The desensitization data is processed by the development project.
  2. 根据权利要求1所述的方法,其中,该方法还包括:The method of claim 1 wherein the method further comprises:
    将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目;Returning the processing result of the desensitization data in the development project to the production project;
    通过所述生产项目发布所述处理结果。The processing result is issued by the production project.
  3. 根据权利要求2所述的方法,其中,该方法还包括:The method of claim 2, wherein the method further comprises:
    设置所述开发项目关于所述脱敏数据的权限信息;Setting permission information of the development item regarding the desensitization data;
    其中,所述将所述脱敏数据发送至对应的开发项目包括:The sending the desensitization data to the corresponding development project includes:
    根据所述权限信息将所述脱敏数据发送至所述开发项目。The desensitization data is sent to the development project based on the permission information.
  4. 一种在数据提供设备端用于进行数据处理的方法,其中,该方法包括:A method for data processing on a data providing device side, wherein the method comprises:
    对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;Desensitizing the production data in the production project to obtain corresponding desensitization data;
    通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;Developing and authorizing the application development project in the corresponding data application device through the development project;
    根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目。The desensitization data is sent to the application development project via the development project according to result information of the development authorization process.
  5. 根据权利要求4所述的方法,其中,该方法还包括:The method of claim 4, wherein the method further comprises:
    通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理;Performing production authorization processing on the application production item in the data application device by the production project;
    根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目。The production data is transmitted to the application production item via the production item according to result information of the production authorization process.
  6. 一种在数据应用设备端用于进行数据处理的方法,其中,该方法包括:A method for data processing on a data application device side, wherein the method includes:
    通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;Desensitizing data from a development item in the data providing device is obtained by an application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
    通过所述应用开发项目处理所述脱敏数据。The desensitization data is processed by the application development project.
  7. 根据权利要求6所述的方法,其中,该方法还包括:The method of claim 6 wherein the method further comprises:
    将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;Providing the processing result of the desensitization data in the application development project to the application production project;
    通过所述应用生产项目发布所述处理结果。The processing result is released by the application production project.
  8. 根据权利要求7所述的方法,其中,该方法还包括:The method of claim 7 wherein the method further comprises:
    通过应用生产项目获取所述数据提供设备中生产项目的生产数据; Obtaining production data of a production item in the data providing device by applying a production project;
    其中,所述通过所述应用生产项目发布所述处理结果包括:Wherein the publishing the processing result by using the application production item comprises:
    根据所述生产数据在所述应用生产项目中执行所述处理结果。The processing result is executed in the application production item based on the production data.
  9. 根据权利要求6至8中任一项所述的方法,其中,该方法还包括:The method of any of claims 6 to 8, wherein the method further comprises:
    对所述应用生产项目中的应用生产数据进行脱敏处理以获得对应的应用脱敏数据;Desensitizing the application production data in the application production project to obtain corresponding application desensitization data;
    其中,所述通过所述应用开发项目处理所述脱敏数据包括:The processing the desensitization data by the application development project includes:
    通过所述应用开发项目处理所述脱敏数据及所述应用脱敏数据。The desensitization data and the application desensitization data are processed by the application development project.
  10. 一种在数据提供设备端用于进行数据处理的方法,其中,该方法包括:A method for data processing on a data providing device side, wherein the method comprises:
    对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;Desensitizing the production data in the data providing device to obtain corresponding desensitization data;
    将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理。The desensitization data is sent to a corresponding platform device for processing by a corresponding data application device.
  11. 根据权利要求10所述的方法,其中,该方法还包括:The method of claim 10, wherein the method further comprises:
    对所述平台设备中的项目进行授权处理。Authorizing processing of items in the platform device.
  12. 一种在数据应用设备端用于进行数据处理的方法,其中,该方法包括:A method for data processing on a data application device side, wherein the method includes:
    配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得。The platform device is configured to process desensitization data obtained by desensitizing the production data in the data providing device.
  13. 根据权利要求12所述的方法,其中,该方法还包括:The method of claim 12, wherein the method further comprises:
    对所述平台设备中的项目进行授权处理。Authorizing processing of items in the platform device.
  14. 一种在平台设备端用于进行数据处理的方法,其中,该方法包括:A method for data processing on a platform device side, wherein the method includes:
    获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Acquiring desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
    根据对应数据应用设备配置平台设备;Configuring the platform device according to the corresponding data application device;
    通过配置后的所述平台设备处理所述脱敏数据。The desensitization data is processed by the configured platform device.
  15. 根据权利要求14所述的方法,其中,该方法还包括:The method of claim 14 wherein the method further comprises:
    在所述平台设备中创建项目;Creating a project in the platform device;
    其中,所述获取来自数据提供设备的脱敏数据包括:Wherein the obtaining desensitization data from the data providing device comprises:
    通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Desensitizing data from the data providing device is obtained by the item, wherein the desensitizing data is obtained by desensitizing the production data in the data providing device;
    其中,所述根据对应数据应用设备配置平台设备包括:The device for configuring the platform according to the corresponding data application device includes:
    根据对应数据应用设备配置所述项目;Configuring the project according to the corresponding data application device;
    其中,所述通过配置后的所述平台设备处理所述脱敏数据包括:The processing the desensitization data by the configured platform device includes:
    通过配置后的所述项目处理所述脱敏数据。 The desensitization data is processed by the configured item.
  16. 根据权利要求15所述的方法,其中,The method of claim 15 wherein
    获取所述数据提供设备及所述数据应用设备对所述项目的授权信息;Obtaining authorization information of the data providing device and the data application device for the item;
    其中,所述通过所述项目获取来自数据提供设备的脱敏数据包括:The obtaining the desensitization data from the data providing device by using the item includes:
    根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。Desensitization data from the data providing device is acquired by the item according to the authorization information, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  17. 根据权利要求16所述的方法,其中,所述项目包括生产项目与开发项目;The method of claim 16 wherein said project comprises a production project and a development project;
    其中,所述获取所述数据提供设备及所述数据应用设备对所述项目的授权信息包括:The obtaining the authorization information of the data providing device and the data application device for the item includes:
    获取所述数据提供设备及所述数据应用设备对所述生产项目的授权信息;Obtaining authorization information of the data providing device and the data application device on the production item;
    其中,所述根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据包括:The obtaining desensitization data from the data providing device by using the item according to the authorization information includes:
    根据所述授权信息通过所述开发项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Desensitizing data from the data providing device is obtained by the development project according to the authorization information, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
    其中,所述根据对应数据应用设备配置所述项目包括:The configuring the item according to the corresponding data application device includes:
    根据对应数据应用设备配置所述开发项目;Configuring the development project according to the corresponding data application device;
    其中,所述通过配置后的所述项目处理所述脱敏数据包括:The processing the desensitization data by the configured item includes:
    通过配置后的所述开发项目处理所述脱敏数据。The desensitization data is processed by the configured development project.
  18. 根据权利要求17所述的方法,其中,该方法还包括:The method of claim 17 wherein the method further comprises:
    将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;Providing the processing result of the desensitization data in the application development project to the application production project;
    通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。The processing result of the desensitization data in the development project is released by the production project.
  19. 根据权利要求17或18所述的方法,其中,该方法还包括:The method of claim 17 or 18, wherein the method further comprises:
    根据所述授权信息通过所述开发项目获取来自所述数据应用设备的应用方脱敏数据,其中,所述应用方脱敏数据通过对所述数据应用设备中的应用方生产数据脱敏处理获得;Obtaining application desensitization data from the data application device through the development item according to the authorization information, wherein the application side desensitization data is obtained by desensitizing the application side production data in the data application device ;
    其中,所述通过配置后的所述开发项目处理所述脱敏数据包括:The processing the desensitization data by the configured development item includes:
    通过配置后的所述开发项目处理所述脱敏数据及所述应用方脱敏数据。The desensitization data and the application desensitization data are processed by the configured development project.
  20. 一种用于进行数据处理的设备,其中,该设备包括:A device for performing data processing, wherein the device comprises:
    数据脱敏装置,用于对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;a data desensitizing device for desensitizing the production data in the production project to obtain corresponding desensitization data;
    脱敏数据发送装置,用于将所述脱敏数据发送至对应的开发项目; a desensitization data transmitting device, configured to send the desensitization data to a corresponding development project;
    脱敏数据处理装置,用于通过所述开发项目处理所述脱敏数据。A desensitization data processing device for processing the desensitization data by the development project.
  21. 根据权利要求20所述的设备,其中,该设备还包括:The device of claim 20, wherein the device further comprises:
    数据处理结果提供装置,用于将所述脱敏数据在所述开发项目中的处理结果返回至所述生产项目;a data processing result providing means for returning the processing result of the desensitization data in the development project to the production item;
    数据处理结果发布装置,用于通过所述生产项目发布所述处理结果。a data processing result issuing device for distributing the processing result by the production item.
  22. 根据权利要求21所述的设备,其中,该设备还包括:The device of claim 21, wherein the device further comprises:
    脱敏数据权限设置装置,用于设置所述开发项目关于所述脱敏数据的权限信息;a desensitization data authority setting device, configured to set permission information of the development item regarding the desensitization data;
    其中,所述脱敏数据发送装置用于:Wherein the desensitization data transmitting device is used to:
    根据所述权限信息将所述脱敏数据发送至所述开发项目。The desensitization data is sent to the development project based on the permission information.
  23. 一种用于进行数据处理的数据提供设备,其中,该设备包括:A data providing device for performing data processing, wherein the device comprises:
    数据脱敏装置,用于对生产项目中的生产数据进行脱敏处理以获得对应的脱敏数据;a data desensitizing device for desensitizing the production data in the production project to obtain corresponding desensitization data;
    开发授权装置,用于通过开发项目对对应数据应用设备中的应用开发项目进行开发授权处理;Developing an authorization device for developing and authorizing the application development project in the corresponding data application device through the development project;
    脱敏数据发送装置,用于根据所述开发授权处理的结果信息将所述脱敏数据经由所述开发项目发送至所述应用开发项目。And a desensitization data transmitting device, configured to send the desensitization data to the application development project via the development project according to result information of the development authorization process.
  24. 根据权利要求23所述的设备,其中,该设备还包括:The device of claim 23, wherein the device further comprises:
    生产授权装置,用于通过所述生产项目对所述数据应用设备中的应用生产项目进行生产授权处理;a production authorization device, configured to perform production authorization processing on the application production item in the data application device by using the production item;
    生产数据发送装置,用于根据所述生产授权处理的结果信息将所述生产数据经由所述生产项目发送至所述应用生产项目。a production data transmitting device for transmitting the production data to the application production item via the production item according to result information of the production authorization process.
  25. 一种用于进行数据处理的数据应用设备,其中,该设备包括:A data application device for performing data processing, wherein the device comprises:
    脱敏数据获取装置,用于通过应用开发项目获取来自数据提供设备中开发项目的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中生产项目的生产数据脱敏处理获得;a desensitization data acquisition device for acquiring desensitization data from a development item in a data providing device by an application development project, wherein the desensitization data is obtained by desensitizing the production data of the production item in the data providing device;
    脱敏数据处理装置,用于通过所述应用开发项目处理所述脱敏数据。A desensitization data processing device for processing the desensitization data by the application development project.
  26. 根据权利要求25所述的设备,其中,该设备还包括:The device of claim 25, wherein the device further comprises:
    数据处理结果提供装置,用于将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;a data processing result providing device, configured to provide the processing result of the desensitization data in the application development project to the application production project;
    数据处理结果发布装置,用于通过所述应用生产项目发布所述处理结果。 And a data processing result issuing device, configured to issue the processing result by the application production item.
  27. 根据权利要求26所述的设备,其中,该设备还包括:The device of claim 26, wherein the device further comprises:
    生产数据获取装置,用于通过应用生产项目获取所述数据提供设备中生产项目的生产数据;a production data obtaining device for acquiring production data of a production item in the data providing device by applying a production project;
    其中,所述数据处理结果发布装置用于:The data processing result publishing device is configured to:
    根据所述生产数据在所述应用生产项目中执行所述处理结果。The processing result is executed in the application production item based on the production data.
  28. 根据权利要求25至27中任一项所述的设备,其中,该设备还包括:The device according to any one of claims 25 to 27, wherein the device further comprises:
    数据脱敏装置,用于对所述应用生产项目中的应用生产数据进行脱敏处理以获得对应的应用脱敏数据;a data desensitizing device, configured to desensitize the application production data in the application production project to obtain corresponding application desensitization data;
    其中,所述脱敏数据处理装置用于:Wherein the desensitization data processing device is used to:
    通过所述应用开发项目处理所述脱敏数据及所述应用脱敏数据。The desensitization data and the application desensitization data are processed by the application development project.
  29. 一种用于进行数据处理的数据提供设备,其中,该设备包括:A data providing device for performing data processing, wherein the device comprises:
    数据脱敏装置,用于对数据提供设备中的生产数据进行脱敏处理以获得对应的脱敏数据;a data desensitizing device, configured to desensitize the production data in the data providing device to obtain corresponding desensitization data;
    脱敏数据发送装置,用于将所述脱敏数据发送至对应的平台设备以供对应的数据应用设备处理。The desensitization data sending device is configured to send the desensitization data to a corresponding platform device for processing by a corresponding data application device.
  30. 根据权利要求29所述的设备,其中,该设备还包括:The device of claim 29, wherein the device further comprises:
    平台授权装置,用于对所述平台设备中的项目进行授权处理。The platform authorization device is configured to perform authorization processing on the items in the platform device.
  31. 一种用于进行数据处理的数据应用设备,其中,该设备包括:A data application device for performing data processing, wherein the device comprises:
    平台配置装置,用于配置平台设备以处理脱敏数据,其中,所述脱敏数据通过对数据提供设备中的生产数据脱敏处理获得。A platform configuration device for configuring the platform device to process desensitization data, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  32. 根据权利要求31所述的设备,其中,该设备还包括:The device of claim 31, wherein the device further comprises:
    平台授权装置,用于对所述平台设备中的项目进行授权处理。The platform authorization device is configured to perform authorization processing on the items in the platform device.
  33. 一种用于进行数据处理的平台设备,其中,该设备包括:A platform device for performing data processing, wherein the device includes:
    脱敏数据获取装置,用于获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Desensitization data acquisition means for acquiring desensitization data from the data providing device, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
    配置装置,用于根据对应数据应用设备配置平台设备;a configuration device, configured to configure a platform device according to the corresponding data application device;
    脱敏数据处理装置,用于通过配置后的所述平台设备处理所述脱敏数据。The desensitization data processing device is configured to process the desensitization data by the configured platform device.
  34. 根据权利要求33所述的设备,其中,该设备还包括:The device of claim 33, wherein the device further comprises:
    平台项目创建装置,用于在所述平台设备中创建项目;a platform project creation device for creating a project in the platform device;
    其中,所述脱敏数据获取装置用于: Wherein the desensitization data acquisition device is used to:
    通过所述项目获取来自数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Desensitizing data from the data providing device is obtained by the item, wherein the desensitizing data is obtained by desensitizing the production data in the data providing device;
    其中,所述配置装置用于:Wherein the configuration device is used to:
    根据对应数据应用设备配置所述项目;Configuring the project according to the corresponding data application device;
    其中,所述脱敏数据处理装置用于:Wherein the desensitization data processing device is used to:
    通过配置后的所述项目处理所述脱敏数据。The desensitization data is processed by the configured item.
  35. 根据权利要求34所述的设备,其中,该设备还包括:The device of claim 34, wherein the device further comprises:
    授权获取装置,用于获取所述数据提供设备及所述数据应用设备对所述项目的授权信息;And an authorization obtaining device, configured to acquire authorization information of the data providing device and the data application device for the item;
    其中,所述脱敏数据获取装置还用于:The desensitization data acquisition device is further configured to:
    根据所述授权信息通过所述项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得。Desensitization data from the data providing device is acquired by the item according to the authorization information, wherein the desensitization data is obtained by desensitizing the production data in the data providing device.
  36. 根据权利要求35所述的设备,其中,所述项目包括生产项目与开发项目;The apparatus according to claim 35, wherein said item comprises a production item and a development item;
    其中,所述授权获取装置用于:Wherein the authorization obtaining device is used to:
    获取所述数据提供设备及所述数据应用设备对所述生产项目的授权信息;Obtaining authorization information of the data providing device and the data application device on the production item;
    其中,所述脱敏数据获取装置用于:Wherein the desensitization data acquisition device is used to:
    根据所述授权信息通过所述开发项目获取来自所述数据提供设备的脱敏数据,其中,所述脱敏数据通过对所述数据提供设备中的生产数据脱敏处理获得;Desensitizing data from the data providing device is obtained by the development project according to the authorization information, wherein the desensitization data is obtained by desensitizing the production data in the data providing device;
    其中,所述配置装置用于:Wherein the configuration device is used to:
    根据对应数据应用设备配置所述开发项目;Configuring the development project according to the corresponding data application device;
    其中,所述脱敏数据处理装置用于:Wherein the desensitization data processing device is used to:
    通过配置后的所述开发项目处理所述脱敏数据。The desensitization data is processed by the configured development project.
  37. 根据权利要求36所述的设备,其中,该设备还包括:The device of claim 36, wherein the device further comprises:
    数据处理结果提供装置,用于将所述脱敏数据在所述应用开发项目中的处理结果提供至所述应用生产项目;a data processing result providing device, configured to provide the processing result of the desensitization data in the application development project to the application production project;
    数据处理结果发布装置,用于通过所述生产项目发布所述脱敏数据在所述开发项目中的处理结果。And a data processing result issuing device, configured to release, by the production item, a processing result of the desensitization data in the development project.
  38. 根据权利要求36或37所述的设备,其中,该设备还包括:The device according to claim 36 or 37, wherein the device further comprises:
    应用方脱敏数据获取装置,用于根据所述授权信息通过所述开发项目获取来自所述数据应用设备的应用方脱敏数据,其中,所述应用方脱敏数据通过对所述数据应用设备 中的应用方生产数据脱敏处理获得;An application-side desensitization data acquisition device, configured to acquire, by the development project, application-side desensitization data from the data application device according to the authorization information, where the application-side desensitization data is applied to the data application device The application side production data is desensitized;
    其中,所述脱敏数据处理装置用于:Wherein the desensitization data processing device is used to:
    通过配置后的所述开发项目处理所述脱敏数据及所述应用方脱敏数据。 The desensitization data and the application desensitization data are processed by the configured development project.
PCT/CN2016/092673 2015-08-10 2016-08-01 Method and device for data processing WO2017024957A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510486640.2 2015-08-10
CN201510486640 2015-08-10

Publications (1)

Publication Number Publication Date
WO2017024957A1 true WO2017024957A1 (en) 2017-02-16

Family

ID=57982970

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/092673 WO2017024957A1 (en) 2015-08-10 2016-08-01 Method and device for data processing

Country Status (2)

Country Link
CN (1) CN106446704A (en)
WO (1) WO2017024957A1 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110489990A (en) * 2018-05-15 2019-11-22 中国移动通信集团浙江有限公司 A kind of sensitive data processing method, device, electronic equipment and storage medium
WO2022048464A1 (en) * 2020-09-01 2022-03-10 华为技术有限公司 Data masking method, data masking apparatus and storage device

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110059081A (en) * 2019-03-13 2019-07-26 深圳壹账通智能科技有限公司 Data output method, device and the computer equipment shown based on data
CN112073465A (en) * 2020-08-07 2020-12-11 上海上讯信息技术股份有限公司 Dynamic desensitization method and device based on SFTP transmission
CN112163214A (en) * 2020-09-22 2021-01-01 杭州数梦工场科技有限公司 Data access method and device
CN112417505A (en) * 2020-11-23 2021-02-26 平安普惠企业管理有限公司 Data processing method, device, equipment and medium
CN112270415B (en) * 2020-11-25 2024-03-22 矩阵元技术(深圳)有限公司 Training data preparation method, device and equipment for encryption machine learning
CN113127929B (en) * 2021-04-30 2024-03-01 天翼安全科技有限公司 Data desensitizing method, desensitizing rule processing method, device, equipment and storage medium
CN114979281B (en) * 2022-07-11 2022-11-08 成都信息工程大学 Data interaction method applied to industrial internet cloud service platform

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080270370A1 (en) * 2007-04-30 2008-10-30 Castellanos Maria G Desensitizing database information
US20080288548A1 (en) * 2007-05-14 2008-11-20 Oracle International Corporation Desensitizing data in cloning
US20090132575A1 (en) * 2007-11-19 2009-05-21 William Kroeschel Masking related sensitive data in groups
CN103778380A (en) * 2013-12-31 2014-05-07 网秦(北京)科技有限公司 Data desensitization method and device and data anti-desensitization method and device
CN104270465A (en) * 2014-10-23 2015-01-07 成都双奥阳科技有限公司 Cloud storage protection system

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101630431B (en) * 2008-07-17 2011-04-13 航天信息股份有限公司 Method for processing multi-client centralized invoicing data
CN105074712B (en) * 2013-03-19 2018-05-08 株式会社东芝 Code processing apparatus and program
CN104618330B (en) * 2014-12-26 2018-12-25 小米科技有限责任公司 Method for processing business, device and terminal

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080270370A1 (en) * 2007-04-30 2008-10-30 Castellanos Maria G Desensitizing database information
US20080288548A1 (en) * 2007-05-14 2008-11-20 Oracle International Corporation Desensitizing data in cloning
US20090132575A1 (en) * 2007-11-19 2009-05-21 William Kroeschel Masking related sensitive data in groups
CN103778380A (en) * 2013-12-31 2014-05-07 网秦(北京)科技有限公司 Data desensitization method and device and data anti-desensitization method and device
CN104270465A (en) * 2014-10-23 2015-01-07 成都双奥阳科技有限公司 Cloud storage protection system

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110489990A (en) * 2018-05-15 2019-11-22 中国移动通信集团浙江有限公司 A kind of sensitive data processing method, device, electronic equipment and storage medium
CN110489990B (en) * 2018-05-15 2021-08-31 中国移动通信集团浙江有限公司 Sensitive data processing method and device, electronic equipment and storage medium
WO2022048464A1 (en) * 2020-09-01 2022-03-10 华为技术有限公司 Data masking method, data masking apparatus and storage device

Also Published As

Publication number Publication date
CN106446704A (en) 2017-02-22

Similar Documents

Publication Publication Date Title
WO2017024957A1 (en) Method and device for data processing
US10547601B2 (en) System and method to allow third-party developer to debug code in customer environment
US10157286B2 (en) Platform for adopting settings to secure a protected file
Stefan et al. Protecting Users by Confining {JavaScript} with {COWL}
US9172724B1 (en) Licensing and authentication with virtual desktop manager
Parekh et al. An analysis of security challenges in cloud computing
US20120272301A1 (en) Controlled user account access with automatically revocable temporary password
US11061999B2 (en) Systems and methods for dynamically enforcing digital rights management via embedded browser
US20170185790A1 (en) Dynamic management of protected file access
US9887842B2 (en) Binding software application bundles to a physical execution medium
US20170187527A1 (en) Obtaining A Decryption Key From a Mobile Device
US11057219B2 (en) Timestamped license data structure
CN114096965A (en) Black box security for containers
KR101627078B1 (en) Apparatus and method for managing password
Grothe et al. How to break microsoft rights management services
TW200905516A (en) Method and system for protecting file data against divulgence
US11244031B2 (en) License data structure including license aggregation
KR101952139B1 (en) A method for providing digital right management function in gateway server communicated with user terminal
KR101643677B1 (en) Securing execution of computational resources
US9733852B2 (en) Encrypted synchronization
EP2947593B1 (en) Security apparatus session sharing
Gremaud et al. Privacy-preserving IoT cloud data processing using SGX
JP2015185071A (en) Information track system and information track method
US20180260541A1 (en) License data structure including location-based application features
CN115577568B (en) Method, device and storage medium for determining operation authority of simulation model

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16834581

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16834581

Country of ref document: EP

Kind code of ref document: A1